# HDFS snapshot java access denied

**URL:** <https://discuss.elastic.co/t/hdfs-snapshot-java-access-denied/100397>\
**Category:** Elasticsearch\
**Tags:** es-hadoop\
**Created:** [September 13, 2017, 6:19pm UTC](https://discuss.elastic.co/t/hdfs-snapshot-java-access-denied/100397 "2017-09-13T18:19:18Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![tarp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tarp/32/51884_2.png) [@tarp](https://discuss.elastic.co/u/tarp)\
**Post date:** [September 13, 2017, 6:19pm UTC](https://discuss.elastic.co/t/hdfs-snapshot-java-access-denied/100397/1 "2017-09-13T18:19:18Z")

</div>

Hi,

I'm trying to setup HDFS as a snapshot respository. I'm able to create the repo. But upon creating the first snapshot, I'm getting these errors.  
"shards": {  
"0": {  
"stage": "FAILURE",  
"stats": {  
"number\_of\_files": 0,  
"processed\_files": 0,  
"total\_size\_in\_bytes": 0,  
"processed\_size\_in\_bytes": 0,  
"start\_time\_in\_millis": 0,  
"time\_in\_millis": 0  
},  
"reason": """IndexShardSnapshotFailedException[Failed to snapshot]; nested: ElasticsearchException[failed to create blob container]; nested: IOException[com.google.protobuf.ServiceException: java.security.AccessControlException: access denied ("javax.security.auth.PrivateCredentialPermission" "org.apache.hadoop.security.Credentials" "read")]; nested: ServiceException[java.security.AccessControlException: access denied ("javax.security.auth.PrivateCredentialPermission" "org.apache.hadoop.security.Credentials" "read")]; nested: AccessControlException[access denied ("javax.security.auth.PrivateCredentialPermission" "org.apache.hadoop.security.Credentials" "read")]; """  
}

I tried to add the JVM Option -Djava.security.policy=file:///usr/share/elasticsearch/plugins/repository-hdfs/plugin-security.policy  
But that didn't help.  
Any ideas?  
Thanks,  
Tim

---

<div class="post-metadata">

**Author:** ![james.baiera](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/james.baiera/32/10209_2.png) [@james.baiera](https://discuss.elastic.co/u/james.baiera)\
**Post date:** [October 4, 2017, 3:18am UTC](https://discuss.elastic.co/t/hdfs-snapshot-java-access-denied/100397/2 "2017-10-04T03:18:47Z")

</div>

Hi @tarp, which version of ES and the plugin are you using?

---

<div class="post-metadata">

**Author:** ![tarp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tarp/32/51884_2.png) [@tarp](https://discuss.elastic.co/u/tarp)\
**Post date:** [October 4, 2017, 1:15pm UTC](https://discuss.elastic.co/t/hdfs-snapshot-java-access-denied/100397/3 "2017-10-04T13:15:02Z")

</div>

Hi James,  
You are a miracle worker, I just tried it and it is working!  
I hadn't worked on this in a while, previously I was on 5.5.2 for ES with the latest plugin I could download. Since then I have upgraded this cluster to 5.6.0 and I believe the puppet module grabs the latest plugin. Anyway, just tried it and it's backing up. So that's good. I will also have to test this on our prod cluster, but I need to talk to our HDFS team first to get the connection info.  
thanks for the reply.  
--Tim

---

<div class="post-metadata">

**Author:** ![james.baiera](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/james.baiera/32/10209_2.png) [@james.baiera](https://discuss.elastic.co/u/james.baiera)\
**Post date:** [October 4, 2017, 1:19pm UTC](https://discuss.elastic.co/t/hdfs-snapshot-java-access-denied/100397/4 "2017-10-04T13:19:40Z")

</div>

@tarp Huh... I'm happy I could help? Let me know if the issue comes back at all

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 1, 2017, 1:20pm UTC](https://discuss.elastic.co/t/hdfs-snapshot-java-access-denied/100397/5 "2017-11-01T13:20:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
