<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: 2.5.3 to 2.6.5 upgrade pre check fails on Ranger - Truststore path or password is not set. in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/2-5-3-to-2-6-5-upgrade-pre-check-fails-on-Ranger-Truststore/m-p/234885#M196705</link>
    <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/11019/mmartofel.html" nodeid="11019"&gt;@Marek Martofel&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Can you please check if you have setup Abari Truststore?&lt;/P&gt;&lt;P&gt;Do you see any '&lt;STRONG&gt;truststore&lt;/STRONG&gt;' related settings in your current or old "/etc/ambari-server/conf/ambari.properties" ?&lt;/P&gt;&lt;PRE&gt;# grep 'trust' /etc/ambari-server/conf/ambari.properties
# grep 'trust' /etc/ambari-server/conf/ambari.properties.rpmsave&lt;/PRE&gt;&lt;P&gt;Based on the error it looks like Your Ranger UI is running on HTTPs and ambari truststore does not have the Ranger certificate imported to it. &lt;/P&gt;&lt;P&gt;You can refer to the following doc to know more about Setting up Truststore for Ambari :  &lt;A href="https://docs.hortonworks.com/HDPDocuments/Ambari-2.6.2.2/bk_ambari-security/content/set_up_truststore_for_ambari_server.html" target="_blank"&gt;https://docs.hortonworks.com/HDPDocuments/Ambari-2.6.2.2/bk_ambari-security/content/set_up_truststore_for_ambari_server.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;.&lt;/P&gt;&lt;P&gt;The following HCC article also explains the cause and remedy of &lt;STRONG&gt;"&lt;EM&gt;Truststore path or password is not set&lt;/EM&gt;" &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.hortonworks.com/articles/39865/enabling-https-for-ambariserver-and-troubleshootin.html" target="_blank"&gt;https://community.hortonworks.com/articles/39865/enabling-https-for-ambariserver-and-troubleshootin.html&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 27 Oct 2018 15:18:53 GMT</pubDate>
    <dc:creator>jsensharma</dc:creator>
    <dc:date>2018-10-27T15:18:53Z</dc:date>
    <item>
      <title>2.5.3 to 2.6.5 upgrade pre check fails on Ranger - Truststore path or password is not set.</title>
      <link>https://community.cloudera.com/t5/Support-Questions/2-5-3-to-2-6-5-upgrade-pre-check-fails-on-Ranger-Truststore/m-p/234884#M196704</link>
      <description>&lt;P&gt;Upgrading 2.5.3 to 2.6.2 , actual Ambari is 2.6.2.2&lt;/P&gt;&lt;P&gt;Last pre check left to resolve. Ranger complains at ambari-server.log :&lt;/P&gt;&lt;PRE&gt;27 Oct 2018 02:41:41,564  INFO [ambari-client-thread-55] RangerSSLConfigCheck:72 - Ranger is SSL enabled, need to show Configuration changes warning before upragade proceeds.
27 Oct 2018 02:42:43,084 ERROR [ambari-client-thread-52] URLStreamProvider:297 - Can't get secure connection to &lt;A href="https://emlpsn01.emprd.lpemrz.com:6182/service/public/api/repository/count" target="_blank"&gt;https://emlpsn01.emprd.lpemrz.com:6182/service/public/api/repository/count&lt;/A&gt;.  Truststore path or password is not set.
27 Oct 2018 02:42:43,085 ERROR [ambari-client-thread-52] CheckHelper:109 - Check SERVICES_RANGER_PASSWORD_VERIFY failed
java.lang.IllegalStateException: Can't get secure connection to &lt;A href="https://emlpsn01.emprd.lpemrz.com:6182/service/public/api/repository/count" target="_blank"&gt;https://emlpsn01.emprd.lpemrz.com:6182/service/public/api/repository/count&lt;/A&gt;.  Truststore path or password is not set.
	at org.apache.ambari.server.controller.internal.URLStreamProvider.getSSLConnection(URLStreamProvider.java:298)
	at org.apache.ambari.server.controller.internal.URLStreamProvider.processURL(URLStreamProvider.java:181)
	at org.apache.ambari.server.controller.internal.URLStreamProvider.processURL(URLStreamProvider.java:160)
	at org.apache.ambari.server.checks.RangerPasswordCheck.checkLogin(RangerPasswordCheck.java:243)
	at org.apache.ambari.server.checks.RangerPasswordCheck.perform(RangerPasswordCheck.java:132)
	at org.apache.ambari.server.state.CheckHelper.performChecks(CheckHelper.java:104)
&lt;/PRE&gt;</description>
      <pubDate>Sat, 27 Oct 2018 15:14:49 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/2-5-3-to-2-6-5-upgrade-pre-check-fails-on-Ranger-Truststore/m-p/234884#M196704</guid>
      <dc:creator>mmartofel</dc:creator>
      <dc:date>2018-10-27T15:14:49Z</dc:date>
    </item>
    <item>
      <title>Re: 2.5.3 to 2.6.5 upgrade pre check fails on Ranger - Truststore path or password is not set.</title>
      <link>https://community.cloudera.com/t5/Support-Questions/2-5-3-to-2-6-5-upgrade-pre-check-fails-on-Ranger-Truststore/m-p/234885#M196705</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/11019/mmartofel.html" nodeid="11019"&gt;@Marek Martofel&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Can you please check if you have setup Abari Truststore?&lt;/P&gt;&lt;P&gt;Do you see any '&lt;STRONG&gt;truststore&lt;/STRONG&gt;' related settings in your current or old "/etc/ambari-server/conf/ambari.properties" ?&lt;/P&gt;&lt;PRE&gt;# grep 'trust' /etc/ambari-server/conf/ambari.properties
# grep 'trust' /etc/ambari-server/conf/ambari.properties.rpmsave&lt;/PRE&gt;&lt;P&gt;Based on the error it looks like Your Ranger UI is running on HTTPs and ambari truststore does not have the Ranger certificate imported to it. &lt;/P&gt;&lt;P&gt;You can refer to the following doc to know more about Setting up Truststore for Ambari :  &lt;A href="https://docs.hortonworks.com/HDPDocuments/Ambari-2.6.2.2/bk_ambari-security/content/set_up_truststore_for_ambari_server.html" target="_blank"&gt;https://docs.hortonworks.com/HDPDocuments/Ambari-2.6.2.2/bk_ambari-security/content/set_up_truststore_for_ambari_server.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;.&lt;/P&gt;&lt;P&gt;The following HCC article also explains the cause and remedy of &lt;STRONG&gt;"&lt;EM&gt;Truststore path or password is not set&lt;/EM&gt;" &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.hortonworks.com/articles/39865/enabling-https-for-ambariserver-and-troubleshootin.html" target="_blank"&gt;https://community.hortonworks.com/articles/39865/enabling-https-for-ambariserver-and-troubleshootin.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 27 Oct 2018 15:18:53 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/2-5-3-to-2-6-5-upgrade-pre-check-fails-on-Ranger-Truststore/m-p/234885#M196705</guid>
      <dc:creator>jsensharma</dc:creator>
      <dc:date>2018-10-27T15:18:53Z</dc:date>
    </item>
    <item>
      <title>Re: 2.5.3 to 2.6.5 upgrade pre check fails on Ranger - Truststore path or password is not set.</title>
      <link>https://community.cloudera.com/t5/Support-Questions/2-5-3-to-2-6-5-upgrade-pre-check-fails-on-Ranger-Truststore/m-p/234886#M196706</link>
      <description>&lt;P&gt;I set same password for admin and amb_ranger_admin as of the instructions from:&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.hortonworks.com/HDPDocuments/HDP2/HDP-2.3.4/bk_Ranger_Install_Guide/content/updating_ranger_admin_passwords.html"&gt;https://docs.hortonworks.com/HDPDocuments/HDP2/HDP-2.3.4/bk_Ranger_Install_Guide/content/updating_ranger_admin_passwords.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;and&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.hortonworks.com/questions/19948/this-alert-is-used-to-ensure-that-the-ranger-admin.html"&gt;https://community.hortonworks.com/questions/19948/this-alert-is-used-to-ensure-that-the-ranger-admin.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.hortonworks.com/questions/19948/this-alert-is-used-to-ensure-that-the-ranger-admin.html"&gt;&lt;/A&gt;Also I created new truststore file as of article:&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.hortonworks.com/articles/16373/ranger-ssl-pitfalls.html"&gt;https://community.hortonworks.com/articles/16373/ranger-ssl-pitfalls.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.hortonworks.com/articles/16373/ranger-ssl-pitfalls.html"&gt;&lt;/A&gt;There is many truststore files and accompaining passwords along Ranger but can't find which one really is considered by upgrade pre check process.&lt;/P&gt;&lt;P&gt;Could you please point me to correct on?&lt;/P&gt;&lt;P&gt;Any more tracing, debugging I can do here?&lt;/P&gt;</description>
      <pubDate>Sat, 27 Oct 2018 15:19:39 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/2-5-3-to-2-6-5-upgrade-pre-check-fails-on-Ranger-Truststore/m-p/234886#M196706</guid>
      <dc:creator>mmartofel</dc:creator>
      <dc:date>2018-10-27T15:19:39Z</dc:date>
    </item>
    <item>
      <title>Re: 2.5.3 to 2.6.5 upgrade pre check fails on Ranger - Truststore path or password is not set.</title>
      <link>https://community.cloudera.com/t5/Support-Questions/2-5-3-to-2-6-5-upgrade-pre-check-fails-on-Ranger-Truststore/m-p/234887#M196707</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/11019/mmartofel.html" nodeid="11019"&gt;@Marek Martofel&lt;BR /&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;So basically you should do the following:&lt;BR /&gt;&lt;BR /&gt;1.  Setup truststore for Ambari Server :  (option-4)&lt;/P&gt;&lt;PRE&gt;# ambari-server setup-seturity
[4] Setup truststore&lt;BR /&gt;&lt;/PRE&gt;&lt;P&gt;&lt;BR /&gt;2.  Import Ranger certificate inside the ambari truststore it can also be done manually or using the following option (option-5)&lt;/P&gt;&lt;PRE&gt;# ambari-server setup-seturity
[5] Import certificate to truststore.&lt;BR /&gt;&lt;/PRE&gt;&lt;P&gt;.&lt;/P&gt;&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/11019/mmartofel.html" nodeid="11019"&gt;&lt;/A&gt; &lt;/P&gt;</description>
      <pubDate>Sat, 27 Oct 2018 15:26:57 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/2-5-3-to-2-6-5-upgrade-pre-check-fails-on-Ranger-Truststore/m-p/234887#M196707</guid>
      <dc:creator>jsensharma</dc:creator>
      <dc:date>2018-10-27T15:26:57Z</dc:date>
    </item>
    <item>
      <title>Re: 2.5.3 to 2.6.5 upgrade pre check fails on Ranger - Truststore path or password is not set.</title>
      <link>https://community.cloudera.com/t5/Support-Questions/2-5-3-to-2-6-5-upgrade-pre-check-fails-on-Ranger-Truststore/m-p/234888#M196708</link>
      <description>&lt;P&gt;YES! This works now! Many thanks for your prompt support Jay!&lt;/P&gt;&lt;P&gt;Will sum up my steps later on for the next folks hitting this issue.&lt;/P&gt;</description>
      <pubDate>Sat, 27 Oct 2018 20:15:33 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/2-5-3-to-2-6-5-upgrade-pre-check-fails-on-Ranger-Truststore/m-p/234888#M196708</guid>
      <dc:creator>mmartofel</dc:creator>
      <dc:date>2018-10-27T20:15:33Z</dc:date>
    </item>
    <item>
      <title>Re: 2.5.3 to 2.6.5 upgrade pre check fails on Ranger - Truststore path or password is not set.</title>
      <link>https://community.cloudera.com/t5/Support-Questions/2-5-3-to-2-6-5-upgrade-pre-check-fails-on-Ranger-Truststore/m-p/234889#M196709</link>
      <description>&lt;P&gt;Have only one line for Kerberos:&lt;/P&gt;&lt;PRE&gt;[mmartofel@emlpsn01 conf]$ grep 'trust' /etc/ambari-server/conf/ambari.properties
kerberos.operation.verify.kdc.trust=true
[mmartofel@emlpsn01 conf]$ grep 'trust' /etc/ambari-server/conf/ambari.properties.rpmsave.20181026104227
[mmartofel@emlpsn01 conf]$
&lt;BR /&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 29 Oct 2018 00:22:51 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/2-5-3-to-2-6-5-upgrade-pre-check-fails-on-Ranger-Truststore/m-p/234889#M196709</guid>
      <dc:creator>mmartofel</dc:creator>
      <dc:date>2018-10-29T00:22:51Z</dc:date>
    </item>
    <item>
      <title>Re: 2.5.3 to 2.6.5 upgrade pre check fails on Ranger - Truststore path or password is not set.</title>
      <link>https://community.cloudera.com/t5/Support-Questions/2-5-3-to-2-6-5-upgrade-pre-check-fails-on-Ranger-Truststore/m-p/234890#M196710</link>
      <description>&lt;P&gt;Let me share my workflow to support anybody hitting this in the future.&lt;/P&gt;&lt;P&gt;Many thanks again Jay!&lt;/P&gt;&lt;PRE&gt;[mmartofel@emlpsn01 certs]$ sudo openssl genrsa -passout pass:hadoop -out $AMBARI_SERVER_HOSTNAME.key 2048
Generating RSA private key, 2048 bit long modulus
.........................................+++
...............................................................+++
e is 65537 (0x10001)
[mmartofel@emlpsn01 certs]$ ll
total 4
-rw-r--r-- 1 root root 1679 Oct 27 14:48 emlpsn01.emprd.lpemrz.com.key
[mmartofel@emlpsn01 certs]$ sudo chown ambari *
[mmartofel@emlpsn01 certs]$ ll
total 4
-rw-r--r-- 1 ambari root 1679 Oct 27 14:48 emlpsn01.emprd.lpemrz.com.key
[mmartofel@emlpsn01 certs]$ sudo openssl req -new -key $AMBARI_SERVER_HOSTNAME.key -out $AMBARI_SERVER_HOSTNAME.csr -subj "/C=DE/ST=Bavaria/L=Minich/O=EMNOS/CN=$AMBARI_SERVER_HOSTNAME"
[mmartofel@emlpsn01 certs]$ ll
total 8
-rw-r--r-- 1 root   root 1001 Oct 27 14:50 emlpsn01.emprd.lpemrz.com.csr
-rw-r--r-- 1 ambari root 1679 Oct 27 14:48 emlpsn01.emprd.lpemrz.com.key
[mmartofel@emlpsn01 certs]$ sudo openssl x509 -req -days 1365 -in $AMBARI_SERVER_HOSTNAME.csr -signkey $AMBARI_SERVER_HOSTNAME.key -out $AMBARI_SERVER_HOSTNAME.crt
Signature ok
subject=/C=DE/ST=Bavaria/L=Minich/O=EMNOS/CN=emlpsn01.emprd.lpemrz.com
Getting Private key
[mmartofel@emlpsn01 certs]$ ll
total 12
-rw-r--r-- 1 root   root 1192 Oct 27 14:51 emlpsn01.emprd.lpemrz.com.crt
-rw-r--r-- 1 root   root 1001 Oct 27 14:50 emlpsn01.emprd.lpemrz.com.csr
-rw-r--r-- 1 ambari root 1679 Oct 27 14:48 emlpsn01.emprd.lpemrz.com.key
[mmartofel@emlpsn01 certs]$ pwd
/etc/ambari-server/certs
[mmartofel@emlpsn01 certs]$ cd ..
[mmartofel@emlpsn01 ambari-server]$ cd conf
[mmartofel@emlpsn01 conf]$ ls -al
total 48
drwxr-xr-x 3 ambari root    248 Oct 27 14:35 .
drwxr-xr-x 7 ambari root    127 Oct 27 14:44 ..
-rwxr-xr-x 1 ambari root   8533 Oct 27 14:40 ambari.properties
-rwxr-xr-x 1 ambari root   7900 Oct 26 10:36 ambari.properties.rpmsave.20181026104227
-rwxr-xr-x 1 ambari root    317 Oct 26 18:24 krb5JAASLogin.conf
-rw-r--r-- 1 ambari ambari  317 Oct 26 18:24 krb5JAASLogin.conf.bak
-rw-r----- 1 ambari root     21 Aug 22 14:59 ldap-password.dat
-rwxr-xr-x 1 ambari root   4929 Oct 26 10:36 log4j.properties
-rwxr-xr-x 1 ambari root   2630 May 29 21:34 metrics.properties
-rw-r----- 1 ambari root     12 Jun  8 16:23 password.dat
drwxr-xr-x 2 ambari root      6 Oct 27 14:35 truststore
[mmartofel@emlpsn01 truststore]$ cd ..
[mmartofel@emlpsn01 conf]$ ls
ambari.properties  ambari.properties.rpmsave.20181026104227  krb5JAASLogin.conf  krb5JAASLogin.conf.bak  ldap-password.dat  log4j.properties  metrics.properties  password.dat  truststore
[mmartofel@emlpsn01 conf]$ pwd
/etc/ambari-server/conf
[mmartofel@emlpsn01 conf]$ sudo mv ./truststore/ /etc/ambari-server/
[mmartofel@emlpsn01 conf]$ ls
ambari.properties  ambari.properties.rpmsave.20181026104227  krb5JAASLogin.conf  krb5JAASLogin.conf.bak  ldap-password.dat  log4j.properties  metrics.properties  password.dat
[mmartofel@emlpsn01 conf]$ ll
total 48
-rwxr-xr-x 1 ambari root   8533 Oct 27 14:40 ambari.properties
-rwxr-xr-x 1 ambari root   7900 Oct 26 10:36 ambari.properties.rpmsave.20181026104227
-rwxr-xr-x 1 ambari root    317 Oct 26 18:24 krb5JAASLogin.conf
-rw-r--r-- 1 ambari ambari  317 Oct 26 18:24 krb5JAASLogin.conf.bak
-rw-r----- 1 ambari root     21 Aug 22 14:59 ldap-password.dat
-rwxr-xr-x 1 ambari root   4929 Oct 26 10:36 log4j.properties
-rwxr-xr-x 1 ambari root   2630 May 29 21:34 metrics.properties
-rw-r----- 1 ambari root     12 Jun  8 16:23 password.dat
[mmartofel@emlpsn01 conf]$ cd ..
[mmartofel@emlpsn01 ambari-server]$ ll
total 0
drwxr-xr-x 2 ambari root 117 Oct 27 14:51 certs
drwxr-xr-x 2 ambari root 230 Oct 27 14:56 conf
drwxr-xr-x 2 ambari root 131 Jun  8 15:22 conf_08_06_18_16_15.save
drwxr-xr-x 2 ambari root 127 Apr 11  2018 conf_12_04_18_10_36.save
drwxr-xr-x 2 ambari root 101 Apr 12  2018 conf_12_04_18_11_25.save
drwxr-xr-x 2 ambari root   6 Oct 27 14:35 truststore
[mmartofel@emlpsn01 truststore]$ pwd
/etc/ambari-server/truststore
[mmartofel@emlpsn01 truststore]$ sudo ambari-server setup-security
Using python  /usr/bin/python
Security setup options...
===========================================================================
Choose one of the following options:
  [1] Enable HTTPS for Ambari server.
  [2] Encrypt passwords stored in ambari.properties file.
  [3] Setup Ambari kerberos JAAS configuration.
  [4] Setup truststore.
  [5] Import certificate to truststore.
===========================================================================
Enter choice, (1-5): 4
Do you want to configure a truststore [y/n] (y)? y
The truststore is already configured. Do you want to re-configure the truststore [y/n] (y)? y
TrustStore type [jks/jceks/pkcs12] (jks):
Path to TrustStore file :/etc/ambari-server/truststore
Password for TrustStore:
Re-enter password:
Ambari Server 'setup-security' completed successfully.
[mmartofel@emlpsn01 truststore]$ pwd
/etc/ambari-server/truststore
[mmartofel@emlpsn01 truststore]$ ll
total 0
[mmartofel@emlpsn01 truststore]$ sudo keytool -import -file /etc/ambari-server/certs/emlpsn01.emprd.lpemrz.com.crt -alias ambari-server -keystore ambari-server-truststore.jks
Enter keystore password:
Re-enter new password:
Owner: CN=emlpsn01.emprd.lpemrz.com, O=EMNOS, L=Minich, ST=Bavaria, C=DE
Issuer: CN=emlpsn01.emprd.lpemrz.com, O=EMNOS, L=Minich, ST=Bavaria, C=DE
Serial number: d2977919873473e6
Valid from: Sat Oct 27 14:51:04 CEST 2018 until: Sat Jul 23 14:51:04 CEST 2022
Certificate fingerprints:
	 MD5:  CA:F2:C2:60:CF:73:81:6C:C9:B8:E6:69:B7:CB:CE:D0
	 SHA1: CA:F7:E0:B6:68:C3:C7:6B:DC:49:3A:10:3C:93:8A:28:52:B2:C2:D6
	 SHA256: B3:50:84:3A:AB:B5:84:0D:A7:8F:0F:12:BC:6D:4B:C4:51:13:E0:A6:D0:CD:F9:A5:A6:E4:72:6D:E6:FF:A8:1C
Signature algorithm name: SHA256withRSA
Subject Public Key Algorithm: 2048-bit RSA key
Version: 1
Trust this certificate? [no]:  yes
Certificate was added to keystore
[mmartofel@emlpsn01 truststore]$ ll
total 4
-rw-r--r-- 1 root root 910 Oct 27 15:03 ambari-server-truststore.jks
[mmartofel@emlpsn01 truststore]$ sudo chown ambari ./*
[mmartofel@emlpsn01 truststore]$ ll
total 4
-rw-r--r-- 1 ambari root 910 Oct 27 15:03 ambari-server-truststore.jks
[mmartofel@emlpsn01 truststore]$ sudo ambari-server setup-security
Using python  /usr/bin/python
Security setup options...
===========================================================================
Choose one of the following options:
  [1] Enable HTTPS for Ambari server.
  [2] Encrypt passwords stored in ambari.properties file.
  [3] Setup Ambari kerberos JAAS configuration.
  [4] Setup truststore.
  [5] Import certificate to truststore.
===========================================================================
Enter choice, (1-5): 4
Do you want to configure a truststore [y/n] (y)?
The truststore is already configured. Do you want to re-configure the truststore [y/n] (y)?
TrustStore type [jks/jceks/pkcs12] (jks):
Path to TrustStore file :/etc/ambari-server/truststore/ambari-server-truststore.jks
Password for TrustStore:
Re-enter password:
Ambari Server 'setup-security' completed successfully.
[mmartofel@emlpsn01 truststore]$
[mmartofel@emlpsn01 truststore]$
[mmartofel@emlpsn01 truststore]$ sudo ambari-server setup-security
Using python  /usr/bin/python
Security setup options...
===========================================================================
Choose one of the following options:
  [1] Enable HTTPS for Ambari server.
  [2] Encrypt passwords stored in ambari.properties file.
  [3] Setup Ambari kerberos JAAS configuration.
  [4] Setup truststore.
  [5] Import certificate to truststore.
===========================================================================
Enter choice, (1-5): 5
Do you want to configure a truststore [y/n] (y)?
Do you want to import a certificate [y/n] (y)?
Please enter an alias for the certificate: ambari-server
Enter path to certificate: /etc/ambari-server/certs/emlpsn01.emprd.lpemrz.com.crt
Ambari Server 'setup-security' completed successfully.
[mmartofel@emlpsn01 truststore]$ ll
total 4
-rw-r--r-- 1 ambari root 910 Oct 27 15:06 ambari-server-truststore.jks
[mmartofel@emlpsn01 truststore]$ sudo keytool --list --keystore ./ambari-server-truststore.jks
Enter keystore password:
Keystore type: JKS
Keystore provider: SUN


Your keystore contains 1 entry


ambari-server, Oct 27, 2018, trustedCertEntry,
Certificate fingerprint (SHA1): CA:F7:E0:B6:68:C3:C7:6B:DC:49:3A:10:3C:93:8A:28:52:B2:C2:D6
[mmartofel@emlpsn01 truststore]$ sudo ambari-server start
Using python  /usr/bin/python
Starting ambari-server
Ambari Server running with administrator privileges.
Organizing resource files at /var/lib/ambari-server/resources...
Ambari database consistency check started...
Server PID at: /var/run/ambari-server/ambari-server.pid
Server out at: /var/log/ambari-server/ambari-server.out
Server log at: /var/log/ambari-server/ambari-server.log
Waiting for server start.......................
Server started listening on 8080


DB configs consistency check: no errors and warnings were found.
Ambari Server 'start' completed successfully.
[mmartofel@emlpsn01 truststore]$ cat /etc/ambari-server/conf/ambari.properties | grep trust
kerberos.operation.verify.kdc.trust=true
ssl.trustStore.password=XXXXXXXXXXXXXXX
ssl.trustStore.path=/etc/ambari-server/truststore/ambari-server-truststore.jks
ssl.trustStore.type=jks
&lt;/PRE&gt;</description>
      <pubDate>Mon, 29 Oct 2018 17:09:31 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/2-5-3-to-2-6-5-upgrade-pre-check-fails-on-Ranger-Truststore/m-p/234890#M196710</guid>
      <dc:creator>mmartofel</dc:creator>
      <dc:date>2018-10-29T17:09:31Z</dc:date>
    </item>
    <item>
      <title>Re: 2.5.3 to 2.6.5 upgrade pre check fails on Ranger - Truststore path or password is not set.</title>
      <link>https://community.cloudera.com/t5/Support-Questions/2-5-3-to-2-6-5-upgrade-pre-check-fails-on-Ranger-Truststore/m-p/234891#M196711</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/11019/mmartofel.html" nodeid="11019"&gt;@Marek Martofel&lt;BR /&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Wonderful!!! thank you for sharing so detailed steps.&lt;/P&gt;&lt;P&gt;I am marking this thread as answered.&lt;BR /&gt;&lt;A rel="user" href="https://community.cloudera.com/users/11019/mmartofel.html" nodeid="11019"&gt;&lt;/A&gt; &lt;/P&gt;</description>
      <pubDate>Mon, 29 Oct 2018 18:18:03 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/2-5-3-to-2-6-5-upgrade-pre-check-fails-on-Ranger-Truststore/m-p/234891#M196711</guid>
      <dc:creator>jsensharma</dc:creator>
      <dc:date>2018-10-29T18:18:03Z</dc:date>
    </item>
  </channel>
</rss>

