    Impala Kerberos Connections in Tableau Server

    Alan Jackoway

      Has anyone had success running extracts or live connections to a Cloudera Impala source with Kerberos in Tableau Server?


      In our environment, Tableau Desktop works and can publish data sources to Tableau Server. The only scheduling and authentication option for these sources is Server Run As account.


      We have found that unless we use remote desktop to log into Tableau Server as the Tableau Server Run As user and get a ticket using MIT Kerberos Ticket Manager, these extracts fail with an error like this:


      [Cloudera][ImpalaODBC] (100) Error from the Impala Thrift API: SASL(-1): generic failure: GSSAPI Error: Unspecified GSS failure. Minor code may provide more information (Credentials cache file 'C:\temp\krb5cache' not found) Unable to connect to the server "server...


      It seems like the Tableau Server user has to stay authenticated outside of Tableau for Impala connections to work. Has anyone found a way to keep Tableau connecting to Impala that is better than logging in with remote desktop and getting Kerberos tickets manually?


      Thanks for your help!