Reply
Highlighted
Explorer
Posts: 25
Registered: ‎07-11-2016

TLS Encryption with trusted public certificate issue

Hi,

 

Below is my scenario.

 

 

1] We already have trusted public CA certificate.

 

2] We have a new cluster where we want to implement the kerberos and as a pre-requisite enabling the TLS encryption.

 

3] Since, cluster is new created the cacerts using command as per below on CM host under /usr/java/jdk1.7.0_67-cloudera/jre/lib/security/.

 

keytool -keystore cacerts -importcert -alias aliasname -file /certificatepath/cert_wildcard_full.pem

 

4] Used the steps mentioned in below link;

https://www.cloudera.com/documentation/enterprise/latest/topics/cm_sg_create_deploy_certs.html

From above link Followed - step[1],step[2]

From above link Not Followed - Since, already have the trusted public CA certificate hence not followed the step[3],step[4],step[5] [Please correct me, if I am wrong]

And then followed step[6] i.e. Import the Certificate into the Keystore

 

5] After doing this followed below link steps.

https://www.cloudera.com/documentation/enterprise/latest/topics/sg_cms_ssl.html

 

6] I have also copied the $JAVA_HOME/jre/lib/security/jssecacerts to all nodes on the cluster and created the cacert on all nodes of the cluster using same command given above in #3.

 

However, when I starts the cloudera server I am getting below error consistently;

 

WARN 1671856335@scm-web-4:org.mortbay.log: javax.net.ssl.SSLHandshakeException: no cipher suites in common

 

Can anybody please help me on this, I have tried various things but not able to fix it and due to this CM is not working.

 

If I am missing anything in above steps or doing anything wrong in above steps can you please confirm what would be the right steps to enable the TLS for trusted public CA.

 

Thank you very much in advance.

 

Really looking out for any assistance on the same.

 

Thanks,

Amit

 

 

 

New Contributor
Posts: 1
Registered: ‎01-18-2019

Re: TLS Encryption with trusted public certificate issue

Hello, 

 

Did you find any results?

 

Thanks in advance.

Announcements