<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: /var/lib/kms-keytrustee/keytrustee/.keytrustee/ is empty in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/var-lib-kms-keytrustee-keytrustee-keytrustee-is-empty/m-p/296885#M218477</link>
    <description>&lt;P&gt;I did follow the similar steps but had the issue. I had to remove all the KTS/KMS installation start from scratch which fixed the issue but this time i added only one server first and then added the other.&lt;/P&gt;</description>
    <pubDate>Fri, 29 May 2020 14:14:54 GMT</pubDate>
    <dc:creator>RajeshBodolla</dc:creator>
    <dc:date>2020-05-29T14:14:54Z</dc:date>
    <item>
      <title>/var/lib/kms-keytrustee/keytrustee/.keytrustee/ is empty</title>
      <link>https://community.cloudera.com/t5/Support-Questions/var-lib-kms-keytrustee-keytrustee-keytrustee-is-empty/m-p/294160#M217094</link>
      <description>&lt;P&gt;I am enabling HDFS data at rest encryption in CDH 6.3 and while adding the KMS service, i noticed that&amp;nbsp;/var/lib/kms-keytrustee/keytrustee/.keytrustee/ is actually doesn't exist on all the KMS hosts when trying to synchronise the KMS hosts private keys. Has anyone come across such issue and what is the way forward for this?&lt;/P&gt;</description>
      <pubDate>Thu, 16 Apr 2020 18:15:03 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/var-lib-kms-keytrustee-keytrustee-keytrustee-is-empty/m-p/294160#M217094</guid>
      <dc:creator>RajeshBodolla</dc:creator>
      <dc:date>2020-04-16T18:15:03Z</dc:date>
    </item>
    <item>
      <title>Re: /var/lib/kms-keytrustee/keytrustee/.keytrustee/ is empty</title>
      <link>https://community.cloudera.com/t5/Support-Questions/var-lib-kms-keytrustee-keytrustee-keytrustee-is-empty/m-p/294434#M217254</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/24123"&gt;@RajeshBodolla&lt;/a&gt;&amp;nbsp;The general steps which I used to follow for Reinstall KTS from scratch this below, might be you are missing something.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;1. Stop the KMS service&lt;BR /&gt;2. Delete the KMS service from the Cloudera Manager UI&lt;BR /&gt;3. Then remove all the contents under "rm -rf /var/lib/kms-keytrustee/"&lt;BR /&gt;&lt;BR /&gt;Note - Make sure that the hidden directory is also removed '/var/lib/kms-keytrustee/keytrustee/.keytrustee'&lt;BR /&gt;&lt;BR /&gt;4. Now sync the Active and passive KTS using the following steps:&lt;BR /&gt;a. Stop the Key Trustee Server service (Key Trustee Server service &amp;gt; Actions &amp;gt; Stop).&lt;BR /&gt;b. Run the following command on the Active Key Trustee Server:&lt;BR /&gt;$ sudo rsync -zav --exclude .ssl /var/lib/keytrustee/.keytrustee &lt;A href="mailto:root@keytrustee02.example.com:/var/lib/keytrustee/" target="_blank"&gt;root@keytrustee02.example.com:/var/lib/keytrustee/&lt;/A&gt;.&lt;BR /&gt;&lt;BR /&gt;Note - Replace keytrustee02.example.com with the hostname of the Passive Key Trustee Server.&lt;BR /&gt;&lt;BR /&gt;c. Run the following command on the Passive Key Trustee Server:&lt;BR /&gt;&lt;BR /&gt;$ sudo ktadmin init&lt;BR /&gt;&lt;BR /&gt;d. Start the Key Trustee Server service (Key Trustee Server service &amp;gt; Actions &amp;gt; Start).&lt;BR /&gt;e. Enable synchronous replication (Key Trustee Server service &amp;gt; Actions &amp;gt; Setup Enable Synchronous Replication in HA mode).&lt;BR /&gt;f. Restart the Key Trustee Server service (Key Trustee Server service &amp;gt; Actions &amp;gt; Restart).&lt;BR /&gt;&lt;BR /&gt;Once this is done, now recreate the KMS service using the steps in the following link&lt;BR /&gt;&lt;BR /&gt;https://www.cloudera.com/documentation/enterprise/latest/topics/key_trustee_kms_ha.html&lt;/PRE&gt;</description>
      <pubDate>Tue, 21 Apr 2020 16:13:03 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/var-lib-kms-keytrustee-keytrustee-keytrustee-is-empty/m-p/294434#M217254</guid>
      <dc:creator>GangWar</dc:creator>
      <dc:date>2020-04-21T16:13:03Z</dc:date>
    </item>
    <item>
      <title>Re: /var/lib/kms-keytrustee/keytrustee/.keytrustee/ is empty</title>
      <link>https://community.cloudera.com/t5/Support-Questions/var-lib-kms-keytrustee-keytrustee-keytrustee-is-empty/m-p/296885#M218477</link>
      <description>&lt;P&gt;I did follow the similar steps but had the issue. I had to remove all the KTS/KMS installation start from scratch which fixed the issue but this time i added only one server first and then added the other.&lt;/P&gt;</description>
      <pubDate>Fri, 29 May 2020 14:14:54 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/var-lib-kms-keytrustee-keytrustee-keytrustee-is-empty/m-p/296885#M218477</guid>
      <dc:creator>RajeshBodolla</dc:creator>
      <dc:date>2020-05-29T14:14:54Z</dc:date>
    </item>
  </channel>
</rss>

