Install the JCE for Kerberos

Before enabling Kerberos in the cluster, you must deploy the Java Cryptography Extension (JCE) security policy files on the Ambari Server and on all hosts in the cluster, including the Ambari Server. If you are using OpenJDK, some distributions of the OpenJDK (such as RHEL/CentOS and Ubuntu) come with unlimited strength JCE automatically and therefore, installation of JCE is not required.

  1. On the Ambari Server, obtain the JCE policy file appropriate for the JDK version in your cluster:
    Oracle JDK 1.8 JCE Unlimited Strength Jurisdiction Policy Files 8 Download
    Oracle JDK 1.7 JCE Unlimited Strength Jurisdiction Policy Files 7 Download
    wget --no-check-certificate --no-cookies --header "Cookie: oraclelicense=accept-securebackup-cookie" ""
  2. Save the policy file archive in a temporary location.
  3. On Ambari Server and on each host in the cluster, add the unlimited security policy JCE jars to $JAVA_HOME/jre/lib/security/.

    For example, run the following to extract the policy jars into the JDK installed on your host:

    unzip -o -j -q -d /usr/jdk64/jdk1.8.0_40/jre/lib/security/
  4. Restart Ambari Server: sudo ambari-server restart.
Proceed to “Running the Kerberos Security Wizard”.