Skip to main content

How to Access Kerberized Hadoop Web UIs Using SPNEGO

Kerberized Hadoop clusters use SPNEGO for browser authentication. To sign into UIs such as NameNode, ResourceManager, Oozie or HiveServer2, your browser must support SPNEGO, your client must have a valid Kerberos ticket and DNS and realm mappings must match. This guide explains how to enable SPNEGO for modern Firefox, Chrome and Edge.

Most Hadoop Web UIs rely on SPNEGO (Simple and Protected GSSAPI Negotiation) to authenticate users through Kerberos. When a browser accesses a Kerberos-protected endpoint such as:

  • http://namenode-host:9870
  • http://rm-host:8088
  • http://oozie-host:11000/oozie

the server expects the browser to negotiate Kerberos credentials automatically. If the browser is not configured correctly, the user will see repeated login prompts or 401: Unauthorized.

Prerequisites

  • You must have a valid Kerberos ticket:
    kinit your_user@YOUR.REALM
  • DNS and reverse DNS for the Hadoop services must be correct
  • The SPN for the UI must match: HTTP/hostname@REALM
  • The browser must allow SPNEGO negotiation for the target domain

Configuring Modern Firefox

Open about:config and set:

  • network.negotiate-auth.trusted-uris: domains where SPNEGO is allowed namenode.company.com, .company.com
  • network.negotiate-auth.delegation-uris: domains allowed for credential delegation .company.com
  • network.negotiate-auth.allow-non-fqdn: set to false unless explicitly needed

Firefox on Linux and macOS uses the system Kerberos libraries and respects /etc/krb5.conf.

Configuring Chrome or Microsoft Edge (Modern Policy-Based Setup)

Modern Chrome and Edge no longer rely on command-line flags for SPNEGO. Instead, they use enterprise policies.

Linux or macOS: JSON policy files

Create (or update) a file:

/etc/opt/chrome/policies/managed/kerberos.json

with content:

{
  "AuthServerWhitelist": "*.company.com",
  "AuthNegotiateDelegateWhitelist": "*.company.com"
}

Windows: Group Policy Editor

Navigate to:

Computer Configuration →
 Administrative Templates →
 Google →
 Google Chrome →
 Authentication

Set:

  • AuthServerWhitelist = *.company.com
  • AuthNegotiateDelegateWhitelist = *.company.com

Configuring Internet Explorer (Legacy Environments)

  • Ensure “Windows Integrated Authentication” is enabled.
  • Add the Hadoop UI domain to Local Intranet sites.
  • Kerberos will only negotiate automatically for intranet zones.

Common Causes of SPNEGO Failure

  • No valid Kerberos ticket (run kinit)
  • Browser not configured to trust the domain
  • DNS mismatch between hostname and Kerberos principal
  • Clock skew between client and KDC
  • Service principal missing: HTTP/hostname@REALM

When SPNEGO Is Not Required

Modern Hadoop deployments often sit behind Apache Knox, identity-aware proxies or SSO systems. These provide access via:

  • SAML or OIDC (Okta, Azure AD, Auth0)
  • JWT-based authentication
  • Token-based API access

In such cases, browser-side Kerberos configuration is unnecessary.

If you need help with distributed systems, backend engineering, or data platforms, check my Services.

Most read articles

Building a Model-Agnostic Multi-Agent System with OpenClaw

Over one week we rebuilt our AI stack around OpenClaw’s multi-agent architecture to avoid provider lock-in and stop wasting premium tokens. By aligning models to tasks, diversifying fallbacks across providers, enforcing minimal tool access, and switching to memory-first workflows with ephemeral sessions, we reduced token usage per task by about 70% and cut our monthly bill by 77% while improving operational resilience. How We Achieved 77% Cost Reduction and Provider Independence Over the past week, we rebuilt our AI infrastructure around OpenClaw’s multi-agent architecture. The result was a 77% cost reduction , provider independence , and a delegation system that routes work to the most cost-effective model for each job. Below is the technical journey of optimizing a 7-agent squad with OpenClaw. The Challenge: Model Provider Lock-In We started with a simple problem: our entire squad defaulted to a single model provider. This created three issues: Cost inefficiency beca...

BacNet => MQTT in Production: The Real Cost of Bridging BACnet to MQTT at Scale

bacnet2mqtt looks simple in a README and expensive in production. Once BACnet polling, reconnection behavior, stale state, and MQTT publishing collide, teams discover they are not deploying a lightweight adapter but operating infrastructure. This article breaks down where bacnet2mqtt works, where it becomes a bottleneck, and which production patterns reduce the operational damage before incidents, backlogs, and silent data loss turn a building integration into a long-running engineering problem. I inherited a building controls integration problem 18 months ago. Three office floors. 217 BACnet sensors covering temperature, occupancy, and HVAC actuators. The data was trapped inside the building automation network while the business wanted analytics, reporting, and compliance visibility in the data platform. The obvious answer looked easy enough: deploy bacnet2mqtt, bridge BACnet into MQTT, and push the stream into the lakehouse stack. The repository made it sound like a w...

Why Is Customer Obsession Disappearing?

Many companies trade real customer-obsession for automated, low-empathy support. Through examples from Coinbase, PayPal, GO Telecommunications and AT&T, this article shows how reliance on AI chatbots, outsourced call centers, and KPI-driven workflows erodes trust, NPS and customer retention. It argues that human-centric support—treating support as strategic investment instead of cost—is still a core growth engine in competitive markets. It's wild that even with all the cool tech we've got these days, like AI solving complex equations and doing business across time zones in a flash, so many companies are still struggling with the basics: taking care of their customers. The drama around Coinbase's customer support is a prime example of even tech giants messing up. And it's not just Coinbase — it's a big-picture issue for the whole industry. At some point, the idea of "customer obsession" got replaced with "customer automation," and no...