Skip to main content

Connecting SQuirreL SQL to HiveServer2 with Kerberos (Updated)

Struggling with delivery, architecture alignment, or platform stability?

I help teams fix systemic engineering issues: processes, architecture, and clarity.
→ See how I work with teams.


Kerberos-secured HiveServer2 environments require proper JAAS configuration, a valid Kerberos ticket and the correct Hive JDBC driver. This updated guide explains how to configure SQuirreL SQL with current Hive JDBC drivers, how Kerberos authentication works today and how to avoid the outdated manual classpath and script edits used in early Hadoop distributions.

SQuirreL SQL remains a lightweight and reliable JDBC client for connecting to HiveServer2, especially in on-prem Kerberized clusters. While older Hadoop versions required assembling dozens of JAR dependencies manually, modern Hive distributions ship a shaded JDBC driver that simplifies configuration significantly.

Prerequisites for Kerberos Authentication

Before launching SQuirreL, ensure that you obtain a valid Kerberos ticket:

kinit your_user@YOUR.REALM

Most Hadoop distributions automatically pick up krb5.conf from system paths (/etc/krb5.conf on Linux, /Library/Preferences on macOS).

If you need to override these settings, create a small JAAS file such as:

KrbClient {
  com.sun.security.auth.module.Krb5LoginModule required
  useTicketCache=true
  renewTGT=true;
};

Then launch SQuirreL with the JAAS and Kerberos system properties:

export JAVA_OPTS="-Djava.security.auth.login.config=jaas.conf \
  -Djavax.security.auth.useSubjectCredsOnly=false"

Modern SQuirreL installations allow you to add JAVA_OPTS via the launcher rather than editing startup scripts.

Adding the Hive JDBC Driver

Use the current “shaded” Hive JDBC driver, which bundles most dependencies:

hive-jdbc-version-standalone.jar

This avoids the large dependency list required by older CDH 4.x and Hive 0.10 clients. Add the shaded JAR via:

  1. Open Drivers in SQuirreL.
  2. Click + to create a new driver.
  3. Enter a name, e.g., HiveServer2 Kerberos.
  4. Driver Class: org.apache.hive.jdbc.HiveDriver
  5. Extra Class Path → Add the shaded JAR.

Connection URL for Kerberos

Use the HiveServer2 Kerberos-enabled URL format:

jdbc:hive2://HOST:PORT/DB;principal=hive/HOST@YOUR.REALM

If you are not using Kerberos, remove the principal portion:

jdbc:hive2://HOST:PORT/DB

No additional JAAS settings are required in non-Kerberos mode.

Java Version Compatibility

Kerberos authentication can fail if the client JVM version mismatches the server’s expectations. If you encounter GSS errors, try matching the JDK major version used on the HiveServer2 host.

Historical Context

Early Hadoop deployments (circa 2014) required:

  • modifying SQuirreL’s startup script
  • manually inserting 15–20 JAR files from CDH or HDP
  • hardcoding Kerberos system properties

Modern distributions ship shaded Hive JDBC drivers and rely on system-level Kerberos configuration, making the process far simpler and more reliable.

For reference, SQuirreL SQL is available at: http://squirrel-sql.sourceforge.net

If you need help with distributed systems, backend engineering, or data platforms, check my Services.

Most read articles

Building a Model-Agnostic Multi-Agent System with OpenClaw

Over one week we rebuilt our AI stack around OpenClaw’s multi-agent architecture to avoid provider lock-in and stop wasting premium tokens. By aligning models to tasks, diversifying fallbacks across providers, enforcing minimal tool access, and switching to memory-first workflows with ephemeral sessions, we reduced token usage per task by about 70% and cut our monthly bill by 77% while improving operational resilience. How We Achieved 77% Cost Reduction and Provider Independence Over the past week, we rebuilt our AI infrastructure around OpenClaw’s multi-agent architecture. The result was a 77% cost reduction , provider independence , and a delegation system that routes work to the most cost-effective model for each job. Below is the technical journey of optimizing a 7-agent squad with OpenClaw. The Challenge: Model Provider Lock-In We started with a simple problem: our entire squad defaulted to a single model provider. This created three issues: Cost inefficiency beca...

BacNet => MQTT in Production: The Real Cost of Bridging BACnet to MQTT at Scale

bacnet2mqtt looks simple in a README and expensive in production. Once BACnet polling, reconnection behavior, stale state, and MQTT publishing collide, teams discover they are not deploying a lightweight adapter but operating infrastructure. This article breaks down where bacnet2mqtt works, where it becomes a bottleneck, and which production patterns reduce the operational damage before incidents, backlogs, and silent data loss turn a building integration into a long-running engineering problem. I inherited a building controls integration problem 18 months ago. Three office floors. 217 BACnet sensors covering temperature, occupancy, and HVAC actuators. The data was trapped inside the building automation network while the business wanted analytics, reporting, and compliance visibility in the data platform. The obvious answer looked easy enough: deploy bacnet2mqtt, bridge BACnet into MQTT, and push the stream into the lakehouse stack. The repository made it sound like a w...

Get Apache Flume 1.3.x running on Windows

Since we found an increasing interest in the flume community to get Apache Flume running on Windows systems again, I spent some time to figure out how we can reach that. Finally, the good news - Apache Flume runs on Windows. You need some tweaks to get them running. Prerequisites Build system: maven 3x, git, jdk1.6.x, WinRAR (or similar program) Apache Flume agent: jdk1.6.x, WinRAR (or similar program), Ultraedit++ or similar texteditor Tweak the Windows build box 1. Download and install JDK 1.6x from Oracle 2. Set the environment variables    => Start - type " env " into the search box, select " E dit system environment variables ", click Environment Variables, Select " New " from the " Systems variables " box, type " JAVA_HOME " into " variable name " and the path to your JDK installation into "Variable value" (Example:  C:\Program Files (x86)\Java\jdk1.6.0_33 ) 3. Download maven from Apache 4. Set...