# HDFS Repository - ES 2.3.3 - Unable to create repo with kerberos

**URL:** <https://discuss.elastic.co/t/hdfs-repository-es-2-3-3-unable-to-create-repo-with-kerberos/58880>\
**Category:** Elasticsearch\
**Tags:** es-hadoop\
**Created:** [August 25, 2016, 2:19am UTC](https://discuss.elastic.co/t/hdfs-repository-es-2-3-3-unable-to-create-repo-with-kerberos/58880 "2016-08-25T02:19:46Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![villamizar](https://avatars.discourse-cdn.com/v4/letter/v/5e9695/32.png) [@villamizar](https://discuss.elastic.co/u/villamizar)\
**Post date:** [August 25, 2016, 2:19am UTC](https://discuss.elastic.co/t/hdfs-repository-es-2-3-3-unable-to-create-repo-with-kerberos/58880/1 "2016-08-25T02:19:46Z")

</div>

I've been trying to create a snapshot repository in an hdfs install configured with kerberos but cannot get it working. Has anybody gotten this working?

**Error (for the commands without uri specified):**  
{"error":{"root\_cause":[{"type":"repository\_verification\_exception","reason":"[esbackup] path is not accessible on master node"}],"type":"repository\_verification\_exception","reason":"[esbackup] path is not accessible on master node","caused\_by":{"type":"i\_o\_exception","reason":"Mkdirs failed to create file:/es\_snap/tests-IcnM9eSiTLuldgMQrDVXuA (exists=false, cwd=file:/usr/share/elasticsearch)"}},"status":500}

**For context:**

- Elasticsearch process is running a the correct user that has hdfs access
- ES\_JAVA\_OPTS has been populated with specifics such as krb5.conf location and pointing to correct KDC.
- As the user that's running elasticsearch, I can create files and folder under the repository directory I'm assigning.
- I can kinit just fine with the keytab provided and can verify all hosts are able to + are defined.

**Different combinations tried so far:**

```
    {"type":"hdfs","settings":{"path":"/es_snap/","compress":"true","user":"username","user_keytab":"/keytabs/username.keytab"}}
    ----
    {"type":"hdfs","settings":{"path":"/es_snap/","compress":"true","user_principal":"username","user_keytab":"/keytabs/username.keytab"}}
    ----
    {"type":"hdfs","settings":{"path":"/es_snap/","compress":"true"}}
    ----
    {"type":"hdfs","settings":{"uri":"hdfs://hostname.com:8020/","path":"/es_snap/","compress":"true"}}
    ----
    {"type":"hdfs","settings":{"uri":"hdfs://hostname.com:8020/","path":"/es_snap/","compress":"true","user_principal":"username","user_keytab":"/keytabs/username.keytab"}}

```

Also, I've noticed that if you specify a uri it switches to simple auth vs kerberos?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:23pm UTC](https://discuss.elastic.co/t/hdfs-repository-es-2-3-3-unable-to-create-repo-with-kerberos/58880/2 "2017-07-06T13:23:33Z")

</div>


