Access to WebHCat with error “User: HTTP/full-domain@REALM is not allowed to impersonate username”

Last week I was dealing with an issue that when connecting to WebHCat using the following command: user got the following error: After doing some research, it turned out to be caused by the auth_to_local rules user defined in the cluster, see below config in the core-site.xml for HDFS: In …