<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Disable/remove auto TLS certificates and create self signed certificate in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/Disable-remove-auto-TLS-certificates-and-create-self-signed/m-p/302687#M221213</link>
    <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/29629"&gt;@GangWar&lt;/a&gt;I am getting this issue while configuring the SSL for Cloudera manager. can you please help me out with this&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2020-09-11 07:03:43,787 ERROR MainThread:com.cloudera.server.cmf.config.components.BeanConfiguration: SSL init failure&lt;BR /&gt;java.io.IOException: Keystore was tampered with, or password was incorrect&lt;BR /&gt;at sun.security.provider.JavaKeyStore.engineLoad(JavaKeyStore.java:780)&lt;BR /&gt;at sun.security.provider.JavaKeyStore$JKS.engineLoad(JavaKeyStore.java:56)&lt;BR /&gt;at sun.security.provider.KeyStoreDelegator.engineLoad(KeyStoreDelegator.java:224)&lt;BR /&gt;at sun.security.provider.JavaKeyStore$DualFormatJKS.engineLoad(JavaKeyStore.java:70)&lt;BR /&gt;at java.security.KeyStore.load(KeyStore.java:1445)&lt;BR /&gt;at org.eclipse.jetty.util.security.CertificateUtils.getKeyStore(CertificateUtils.java:54)&lt;BR /&gt;at org.eclipse.jetty.util.ssl.SslContextFactory.loadTrustStore(SslContextFactory.java:1158)&lt;BR /&gt;at org.eclipse.jetty.util.ssl.SslContextFactory.load(SslContextFactory.java:315)&lt;BR /&gt;at org.eclipse.jetty.util.ssl.SslContextFactory.doStart(SslContextFactory.java:248)&lt;BR /&gt;at org.eclipse.jetty.util.component.AbstractLifeCycle.start(AbstractLifeCycle.java:68)&lt;BR /&gt;at com.cloudera.server.cmf.config.components.BeanConfiguration.getSslContextFactory(BeanConfiguration.java:126)&lt;BR /&gt;at com.cloudera.server.cmf.config.components.BeanConfiguration$$EnhancerBySpringCGLIB$$dea6ffb3.CGLIB$getSslContextFactory$3(&amp;lt;generated&amp;gt;)&lt;BR /&gt;at com.cloudera.server.cmf.config.components.BeanConfiguration$$EnhancerBySpringCGLIB$$dea6ffb3$$FastClassBySpringCGLIB$$15a496c1.invoke(&amp;lt;generated&amp;gt;)&lt;BR /&gt;at org.springframework.cglib.proxy.MethodProxy.invokeSuper(MethodProxy.java:228)&lt;BR /&gt;at org.springframework.context.annotation.ConfigurationClassEnhancer$BeanMethodInterceptor.intercept(ConfigurationClassEnhancer.java:358)&lt;BR /&gt;at com.cloudera.server.cmf.config.components.BeanConfiguration$$EnhancerBySpringCGLIB$$dea6ffb3.getSslContextFactory(&amp;lt;generated&amp;gt;)&lt;BR /&gt;at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)&lt;BR /&gt;at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62)&lt;BR /&gt;at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)&lt;BR /&gt;at java.lang.reflect.Method.invoke(Method.java:498)&lt;BR /&gt;at org.springframework.beans.factory.support.SimpleInstantiationStrategy.instantiate(SimpleInstantiationStrategy.java:162)&lt;BR /&gt;at org.springframework.beans.factory.support.ConstructorResolver.instantiateUsingFactoryMethod(ConstructorResolver.java:588)&lt;BR /&gt;at org.springframework.beans.factory.support.AbstractAutowireCapableBeanFactory.instantiateUsingFactoryMethod(AbstractAutowireCapableBeanFactory.java:1178)&lt;BR /&gt;at org.springframework.beans.factory.support.AbstractAutowireCapableBeanFactory.createBeanInstance(AbstractAutowireCapableBeanFactory.java:1072)&lt;BR /&gt;at org.springframework.beans.factory.support.AbstractAutowireCapableBeanFactory.doCreateBean(AbstractAutowireCapableBeanFactory.java:511)&lt;BR /&gt;at org.springframework.beans.factory.support.AbstractAutowireCapableBeanFactory.createBean(AbstractAutowireCapableBeanFactory.java:481)&lt;BR /&gt;at org.springframework.beans.factory.support.AbstractBeanFactory$1.getObject(AbstractBeanFactory.java:312)&lt;BR /&gt;at org.springframework.beans.factory.support.DefaultSingletonBeanRegistry.getSingleton(DefaultSingletonBeanRegistry.java:230)&lt;BR /&gt;at org.springframework.beans.factory.support.AbstractBeanFactory.doGetBean(AbstractBeanFactory.java:308)&lt;BR /&gt;at org.springframework.beans.factory.support.AbstractBeanFactory.getBean(AbstractBeanFactory.java:202)&lt;BR /&gt;at org.springframework.beans.factory.config.DependencyDescriptor.resolveCandidate(DependencyDescriptor.java:208)&lt;BR /&gt;at org.springframework.beans.factory.support.DefaultListableBeanFactory.doResolveDependency(DefaultListableBeanFactory.java:1136)&lt;BR /&gt;at org.springframework.beans.factory.support.DefaultListableBeanFactory.resolveDependency(DefaultListableBeanFactory.java:1064)&lt;BR /&gt;at org.springframework.beans.factory.support.ConstructorResolver.resolveAutowiredArgument(ConstructorResolver.java:835)&lt;BR /&gt;at org.springframework.beans.factory.support.ConstructorResolver.createArgumentArray(ConstructorResolver.java:741)&lt;BR /&gt;at org.springframework.beans.factory.support.ConstructorResolver.instantiateUsingFactoryMethod(ConstructorResolver.java:467)&lt;BR /&gt;at org.springframework.beans.factory.support.AbstractAutowireCapableBeanFactory.instantiateUsingFactoryMethod(AbstractAutowireCapableBeanFactory.java:1178)&lt;BR /&gt;at org.springframework.beans.factory.support.AbstractAutowireCapableBeanFactory.createBeanInstance(AbstractAutowireCapableBeanFactory.java:1072)&lt;BR /&gt;at org.springframework.beans.factory.support.AbstractAutowireCapableBeanFactory.doCreateBean(AbstractAutowireCapableBeanFactory.java:511)&lt;BR /&gt;at org.springframework.beans.factory.support.AbstractAutowireCapableBeanFactory.createBean(AbstractAutowireCapableBeanFactory.java:481)&lt;BR /&gt;at org.springframework.beans.factory.support.AbstractBeanFactory$1.getObject(AbstractBeanFactory.java:312)&lt;BR /&gt;at org.springframework.beans.factory.support.DefaultSingletonBeanRegistry.getSingleton(DefaultSingletonBeanRegistry.java:230)&lt;BR /&gt;at org.springframework.beans.factory.support.AbstractBeanFactory.doGetBean(AbstractBeanFactory.java:308)&lt;BR /&gt;at org.springframework.beans.factory.support.AbstractBeanFactory.getBean(AbstractBeanFactory.java:202)&lt;BR /&gt;at org.springframework.beans.factory.config.DependencyDescriptor.resolveCandidate(DependencyDescriptor.java:208)&lt;BR /&gt;at org.springframework.beans.factory.support.DefaultListableBeanFactory.doResolveDependency(DefaultListableBeanFactory.java:1136)&lt;BR /&gt;at org.springframework.beans.factory.support.DefaultListableBeanFactory.resolveDependency(DefaultListableBeanFactory.java:1064)&lt;BR /&gt;at org.springframework.beans.factory.support.ConstructorResolver.resolveAutowiredArgument(ConstructorResolver.java:835)&lt;BR /&gt;at org.springframework.beans.factory.support.ConstructorResolver.createArgumentArray(ConstructorResolver.java:741)&lt;BR /&gt;at org.springframework.beans.factory.support.ConstructorResolver.autowireConstructor(ConstructorResolver.java:189)&lt;BR /&gt;at org.springframework.beans.factory.support.AbstractAutowireCapableBeanFactory.autowireConstructor(AbstractAutowireCapableBeanFactory.java:1198)&lt;BR /&gt;at org.springframework.beans.factory.support.AbstractAutowireCapableBeanFactory.createBeanInstance(AbstractAutowireCapableBeanFactory.java:1100)&lt;BR /&gt;at org.springframework.beans.factory.support.AbstractAutowireCapableBeanFactory.doCreateBean(AbstractAutowireCapableBeanFactory.java:511)&lt;BR /&gt;at org.springframework.beans.factory.support.AbstractAutowireCapableBeanFactory.createBean(AbstractAutowireCapableBeanFactory.java:481)&lt;BR /&gt;at org.springframework.beans.factory.support.AbstractBeanFactory$1.getObject(AbstractBeanFactory.java:312)&lt;BR /&gt;at org.springframework.beans.factory.support.DefaultSingletonBeanRegistry.getSingleton(DefaultSingletonBeanRegistry.java:230)&lt;BR /&gt;at org.springframework.beans.factory.support.AbstractBeanFactory.doGetBean(AbstractBeanFactory.java:308)&lt;BR /&gt;at org.springframework.beans.factory.support.AbstractBeanFactory.getBean(AbstractBeanFactory.java:197)&lt;BR /&gt;at org.springframework.beans.factory.support.DefaultListableBeanFactory.preInstantiateSingletons(DefaultListableBeanFactory.java:761)&lt;BR /&gt;at org.springframework.context.support.AbstractApplicationContext.finishBeanFactoryInitialization(AbstractApplicationContext.java:867)&lt;BR /&gt;at org.springframework.context.support.AbstractApplicationContext.refresh(AbstractApplicationContext.java:543)&lt;BR /&gt;at org.springframework.context.support.ClassPathXmlApplicationContext.&amp;lt;init&amp;gt;(ClassPathXmlApplicationContext.java:139)&lt;BR /&gt;at org.springframework.context.support.ClassPathXmlApplicationContext.&amp;lt;init&amp;gt;(ClassPathXmlApplicationContext.java:105)&lt;BR /&gt;at sun.reflect.NativeConstructorAccessorImpl.newInstance0(Native Method)&lt;BR /&gt;at sun.reflect.NativeConstructorAccessorImpl.newInstance(NativeConstructorAccessorImpl.java:62)&lt;BR /&gt;at sun.reflect.DelegatingConstructorAccessorImpl.newInstance(DelegatingConstructorAccessorImpl.java:45)&lt;BR /&gt;at java.lang.reflect.Constructor.newInstance(Constructor.java:423)&lt;BR /&gt;at org.springframework.beans.BeanUtils.instantiateClass(BeanUtils.java:142)&lt;BR /&gt;at org.springframework.beans.factory.support.SimpleInstantiationStrategy.instantiate(SimpleInstantiationStrategy.java:122)&lt;BR /&gt;at org.springframework.beans.factory.support.ConstructorResolver.autowireConstructor(ConstructorResolver.java:271)&lt;BR /&gt;at org.springframework.beans.factory.support.AbstractAutowireCapableBeanFactory.autowireConstructor(AbstractAutowireCapableBeanFactory.java:1198)&lt;BR /&gt;at org.springframework.beans.factory.support.AbstractAutowireCapableBeanFactory.createBeanInstance(AbstractAutowireCapableBeanFactory.java:1100)&lt;BR /&gt;at org.springframework.beans.factory.support.AbstractAutowireCapableBeanFactory.doCreateBean(AbstractAutowireCapableBeanFactory.java:511)&lt;BR /&gt;at org.springframework.beans.factory.support.AbstractAutowireCapableBeanFactory.createBean(AbstractAutowireCapableBeanFactory.java:481)&lt;BR /&gt;at org.springframework.beans.factory.support.AbstractBeanFactory$1.getObject(AbstractBeanFactory.java:312)&lt;BR /&gt;at org.springframework.beans.factory.support.DefaultSingletonBeanRegistry.getSingleton(DefaultSingletonBeanRegistry.java:230)&lt;BR /&gt;at org.springframework.beans.factory.support.AbstractBeanFactory.doGetBean(AbstractBeanFactory.java:308)&lt;BR /&gt;at org.springframework.beans.factory.support.AbstractBeanFactory.getBean(AbstractBeanFactory.java:202)&lt;BR /&gt;at org.springframework.context.support.AbstractApplicationContext.getBean(AbstractApplicationContext.java:1086)&lt;BR /&gt;at org.springframework.beans.factory.access.SingletonBeanFactoryLocator.useBeanFactory(SingletonBeanFactoryLocator.java:396)&lt;BR /&gt;at com.cloudera.server.cmf.Main.findBeanFactory(Main.java:481)&lt;BR /&gt;at com.cloudera.server.cmf.Main.findRootApplicationContext(Main.java:476)&lt;BR /&gt;at com.cloudera.server.cmf.Main.&amp;lt;init&amp;gt;(Main.java:285)&lt;BR /&gt;at com.cloudera.server.cmf.Main.main(Main.java:233)&lt;BR /&gt;Caused by: java.security.UnrecoverableKeyException: Password verification failed&lt;BR /&gt;at sun.security.provider.JavaKeyStore.engineLoad(JavaKeyStore.java:778)&lt;BR /&gt;... 83 more&lt;BR /&gt;2020-09-11 07:03:43,883 INFO MainThread:com.cloudera.server.cmf.Main: Server locale set to: en&lt;BR /&gt;2020-09-11 07:03:43,894 INFO MainThread:com.cloudera.server.cmf.components.EmbeddedDbManager: CM server is NOT using embedded postgresql database for itself.&lt;BR /&gt;2020-09-11 07:03:43,901 INFO MainThread:com.cloudera.cmf.service.CommandScheduleListener: Adding command schedule listener for global-collect-host-statistics&lt;BR /&gt;2020-09-11 07:03:43,905 INFO MainThread:com.cloudera.cmf.service.CommandScheduleListener: Initializing schedule for global-collect-host-statistics&lt;BR /&gt;2020-09-11 07:03:43,907 INFO MainThread:com.cloudera.cmf.command.datacollection.ClusterStatsCommandScheduler: No license - using free bundle settings&lt;BR /&gt;2020-09-11 07:03:43,911 INFO MainThread:com.cloudera.cmf.service.CommandScheduleListener: Replacing existing schedule for global-collect-host-statistics&lt;BR /&gt;2020-09-11 07:03:43,958 INFO MainThread:com.cloudera.cmf.service.CommandScheduleListener: Removed schedule DbCommandSchedule{id=71, commandName=global-collect-host-statistics, displayName=null, description=null}&lt;BR /&gt;2020-09-11 07:03:43,960 INFO MainThread:com.cloudera.cmf.service.CommandScheduleListener: Adding schedule - DbCommandSchedule{id=72, commandName=global-collect-host-statistics, displayName=null, description=null}&lt;BR /&gt;2020-09-11 07:03:43,983 INFO MainThread:com.cloudera.cmf.scheduler.CmfScheduler: Added command schedule '72' to the scheduler&lt;BR /&gt;2020-09-11 07:03:44,047 INFO MainThread:com.cloudera.server.cmf.Main: Starting Auto Upgrade&lt;BR /&gt;2020-09-11 07:03:44,050 INFO MainThread:com.cloudera.cmf.service.upgrade.AutoUpgradeHandlerRegistry: No Auto Upgrades required.&lt;BR /&gt;2020-09-11 07:03:44,050 INFO MainThread:com.cloudera.server.cmf.Main: Successfully completed Auto Upgrade&lt;BR /&gt;2020-09-11 07:03:44,163 INFO MainThread:com.cloudera.server.cmf.Main: Agent RPC connections will use port: 7182&lt;BR /&gt;2020-09-11 07:03:44,163 INFO MainThread:com.cloudera.server.cmf.Main: Agent TLS certificates will be validated.&lt;BR /&gt;2020-09-11 07:03:44,185 INFO MainThread:com.cloudera.server.common.HttpConnectorServer: Max heartbeat processing thread: 25 and Max threads for CM agent avro http connector: 200&lt;BR /&gt;2020-09-11 07:03:44,307 INFO MainThread:com.cloudera.server.common.HttpConnectorServer: HttpConnectorServer port=7182&lt;BR /&gt;2020-09-11 07:03:44,307 INFO MainThread:com.cloudera.server.common.HttpConnectorServer: HttpConnectorServer IdleTime=300000&lt;BR /&gt;2020-09-11 07:03:44,343 INFO MainThread:org.eclipse.jetty.server.Server: jetty-9.4.14.v20181114; built: 2018-11-14T21:20:31.478Z; git: c4550056e785fb5665914545889f21dc136ad9e6; jvm 1.8.0_181-b13&lt;BR /&gt;2020-09-11 07:03:44,375 WARN MainThread:org.eclipse.jetty.security.SecurityHandler: ServletContext@o.e.j.s.ServletContextHandler@b51e1e1{/,null,STARTING} has uncovered http methods for path: /*&lt;BR /&gt;2020-09-11 07:03:44,385 INFO MainThread:org.eclipse.jetty.server.handler.ContextHandler: Started o.e.j.s.ServletContextHandler@b51e1e1{/,null,AVAILABLE}&lt;BR /&gt;2020-09-11 07:03:44,394 ERROR MainThread:com.cloudera.server.cmf.Main: Failed to start Agent listener.&lt;BR /&gt;2020-09-11 07:03:44,394 ERROR MainThread:com.cloudera.server.cmf.Main: Server failed.&lt;BR /&gt;org.apache.avro.AvroRuntimeException: java.io.IOException: Keystore was tampered with, or password was incorrect&lt;BR /&gt;at com.cloudera.server.common.HttpConnectorServer.start(HttpConnectorServer.java:224)&lt;BR /&gt;at com.cloudera.server.cmf.Main.startAgentServer(Main.java:554)&lt;BR /&gt;at com.cloudera.server.cmf.Main.run(Main.java:606)&lt;BR /&gt;at com.cloudera.server.cmf.Main.main(Main.java:234)&lt;BR /&gt;Caused by: java.io.IOException: Keystore was tampered with, or password was incorrect&lt;BR /&gt;at sun.security.provider.JavaKeyStore.engineLoad(JavaKeyStore.java:780)&lt;BR /&gt;at sun.security.provider.JavaKeyStore$JKS.engineLoad(JavaKeyStore.java:56)&lt;BR /&gt;at sun.security.provider.KeyStoreDelegator.engineLoad(KeyStoreDelegator.java:224)&lt;BR /&gt;at sun.security.provider.JavaKeyStore$DualFormatJKS.engineLoad(JavaKeyStore.java:70)&lt;BR /&gt;at java.security.KeyStore.load(KeyStore.java:1445)&lt;BR /&gt;at org.eclipse.jetty.util.security.CertificateUtils.getKeyStore(CertificateUtils.java:54)&lt;BR /&gt;at org.eclipse.jetty.util.ssl.SslContextFactory.loadTrustStore(SslContextFactory.java:1158)&lt;BR /&gt;at org.eclipse.jetty.util.ssl.SslContextFactory.load(SslContextFactory.java:315)&lt;BR /&gt;at org.eclipse.jetty.util.ssl.SslContextFactory.doStart(SslContextFactory.java:248)&lt;BR /&gt;at org.eclipse.jetty.util.component.AbstractLifeCycle.start(AbstractLifeCycle.java:68)&lt;BR /&gt;at org.eclipse.jetty.util.component.ContainerLifeCycle.start(ContainerLifeCycle.java:138)&lt;BR /&gt;at org.eclipse.jetty.util.component.ContainerLifeCycle.doStart(ContainerLifeCycle.java:117)&lt;BR /&gt;at org.eclipse.jetty.server.SslConnectionFactory.doStart(SslConnectionFactory.java:94)&lt;BR /&gt;at org.eclipse.jetty.util.component.AbstractLifeCycle.start(AbstractLifeCycle.java:68)&lt;BR /&gt;at org.eclipse.jetty.util.component.ContainerLifeCycle.start(ContainerLifeCycle.java:138)&lt;BR /&gt;at org.eclipse.jetty.util.component.ContainerLifeCycle.doStart(ContainerLifeCycle.java:117)&lt;BR /&gt;at org.eclipse.jetty.server.AbstractConnector.doStart(AbstractConnector.java:282)&lt;BR /&gt;at org.eclipse.jetty.server.AbstractNetworkConnector.doStart(AbstractNetworkConnector.java:81)&lt;BR /&gt;at org.eclipse.jetty.server.ServerConnector.doStart(ServerConnector.java:236)&lt;BR /&gt;at org.eclipse.jetty.util.component.AbstractLifeCycle.start(AbstractLifeCycle.java:68)&lt;BR /&gt;at org.eclipse.jetty.server.Server.doStart(Server.java:394)&lt;BR /&gt;at org.eclipse.jetty.util.component.AbstractLifeCycle.start(AbstractLifeCycle.java:68)&lt;BR /&gt;at com.cloudera.server.common.HttpConnectorServer.start(HttpConnectorServer.java:222)&lt;BR /&gt;... 3 more&lt;BR /&gt;Caused by: java.security.UnrecoverableKeyException: Password verification failed&lt;BR /&gt;at sun.security.provider.JavaKeyStore.engineLoad(JavaKeyStore.java:778)&lt;BR /&gt;... 25 more&lt;BR /&gt;2020-09-11 07:03:53,644 INFO ScmActive-0:com.cloudera.server.cmf.components.ScmActive: ScmActive completed successfull&lt;/P&gt;</description>
    <pubDate>Fri, 11 Sep 2020 11:05:28 GMT</pubDate>
    <dc:creator>vaibhavm</dc:creator>
    <dc:date>2020-09-11T11:05:28Z</dc:date>
    <item>
      <title>Disable/remove auto TLS certificates and create self signed certificate</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Disable-remove-auto-TLS-certificates-and-create-self-signed/m-p/302507#M221145</link>
      <description>&lt;P&gt;How to disable/remove auto TLS certificates and create self-signed certificate in Cloudera version 6.2. The Cloudera version I am using is 6.2 having self-signed certificates that expired a few days back. now the Cloudera manager is not restarting. I want to remove the existing ones and create a new self-signed certificate and apply it to the cluster. can anyone help?&lt;/P&gt;</description>
      <pubDate>Tue, 08 Sep 2020 09:45:04 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Disable-remove-auto-TLS-certificates-and-create-self-signed/m-p/302507#M221145</guid>
      <dc:creator>vaibhavm</dc:creator>
      <dc:date>2020-09-08T09:45:04Z</dc:date>
    </item>
    <item>
      <title>Re: Disable/remove auto TLS certificates and create self signed certificate</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Disable-remove-auto-TLS-certificates-and-create-self-signed/m-p/302578#M221172</link>
      <description>&lt;P&gt;According to this &lt;A href="https://docs.cloudera.com/documentation/enterprise/6/6.2/topics/how_to_renew_certs_tls.html#certificate-expired-workaround" target="_self"&gt;link&lt;/A&gt;, you should renew and replace the certificates and points to the procedure just above the link.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Sep 2020 14:44:46 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Disable-remove-auto-TLS-certificates-and-create-self-signed/m-p/302578#M221172</guid>
      <dc:creator>Mike in Austin</dc:creator>
      <dc:date>2020-09-09T14:44:46Z</dc:date>
    </item>
    <item>
      <title>Re: Disable/remove auto TLS certificates and create self signed certificate</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Disable-remove-auto-TLS-certificates-and-create-self-signed/m-p/302610#M221183</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/15492"&gt;@Mike in Austin&lt;/a&gt;&amp;nbsp;Thanks for the reply. how can I completely disable the SSL in the cluster? SSL was configured with auto-tls enabled&lt;/P&gt;</description>
      <pubDate>Thu, 10 Sep 2020 08:01:38 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Disable-remove-auto-TLS-certificates-and-create-self-signed/m-p/302610#M221183</guid>
      <dc:creator>vaibhavm</dc:creator>
      <dc:date>2020-09-10T08:01:38Z</dc:date>
    </item>
    <item>
      <title>Re: Disable/remove auto TLS certificates and create self signed certificate</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Disable-remove-auto-TLS-certificates-and-create-self-signed/m-p/302613#M221186</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/81371"&gt;@vaibhavm&lt;/a&gt;&amp;nbsp;You need two steps process.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Disable TLS for CM so that you can access Web UI, for this follow below instruction.&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;Disable TLS for the CM:&lt;BR /&gt;&lt;BR /&gt;1. Determine Cloudera Manager Database&lt;BR /&gt;&lt;BR /&gt;cat /etc/cloudera-scm-server/db.properties&lt;BR /&gt;&lt;BR /&gt;2. Make database backup&lt;BR /&gt;&lt;BR /&gt;3. get inside the DB.&amp;nbsp;&lt;BR /&gt;#mysql --user=cm --password=cm&lt;BR /&gt;#mysql&amp;gt; show databases;&lt;BR /&gt;#mysql&amp;gt; use cm;&lt;BR /&gt;&lt;BR /&gt;4. Show TLS related rows &lt;BR /&gt;select * from CONFIGS where attr like '%tls%';&lt;BR /&gt;&lt;BR /&gt;5. Update TLS for web_tls &lt;BR /&gt;update CONFIGS set value = 'false' where attr = 'web_tls';&lt;BR /&gt;&lt;BR /&gt;6. Update TLS for agent_tls &lt;BR /&gt;update CONFIGS set value = 'false' where attr = 'agent_tls';&lt;BR /&gt;&lt;BR /&gt;7. Show TLS related rows &lt;BR /&gt;select * from CONFIGS where attr like '%tls%';&lt;BR /&gt;&lt;BR /&gt;8. Restart Cloudera Manager server process&lt;BR /&gt;service cloudera-scm-server restart&lt;/PRE&gt;&lt;P&gt;2. At this stage you will be able to successfully login into CM Web UI. Now you can disable Auto-TLS (If already enabled) using below method.&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;--remove the line in /etc/default/cloudera-scm-server that loads cm_init.txt on startup&lt;BR /&gt;--then you can turn off TLS in the web UI and remove the TLS configs from the agent config.ini&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;3. Then you can follow the doc which&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/15492"&gt;@Mike in Austin&lt;/a&gt;&amp;nbsp;refereed in his comment to enable TLS again from fresh.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Sep 2020 08:32:58 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Disable-remove-auto-TLS-certificates-and-create-self-signed/m-p/302613#M221186</guid>
      <dc:creator>GangWar</dc:creator>
      <dc:date>2020-09-10T08:32:58Z</dc:date>
    </item>
    <item>
      <title>Re: Disable/remove auto TLS certificates and create self signed certificate</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Disable-remove-auto-TLS-certificates-and-create-self-signed/m-p/302616#M221187</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/29629"&gt;@GangWar&lt;/a&gt;done what you said. but now I am not able to login with the default username password admin/admin. can you please help with this?&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="clouderaloginpage.png" style="width: 999px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/28858iD1C5CDB2DDFEE02C/image-size/large?v=v2&amp;amp;px=999" role="button" title="clouderaloginpage.png" alt="clouderaloginpage.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="clouderalogs.png" style="width: 999px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/28859i0623638957075CFC/image-size/large?v=v2&amp;amp;px=999" role="button" title="clouderalogs.png" alt="clouderalogs.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Sep 2020 10:23:53 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Disable-remove-auto-TLS-certificates-and-create-self-signed/m-p/302616#M221187</guid>
      <dc:creator>vaibhavm</dc:creator>
      <dc:date>2020-09-10T10:23:53Z</dc:date>
    </item>
    <item>
      <title>Re: Disable/remove auto TLS certificates and create self signed certificate</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Disable-remove-auto-TLS-certificates-and-create-self-signed/m-p/302638#M221201</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/81371"&gt;@vaibhavm&lt;/a&gt;&amp;nbsp;Log says it's successful. Try with another browser else you might need to &lt;A href="https://community.cloudera.com/t5/Support-Questions/How-to-reset-the-admin-password-of-the-Cloudera-Manager/m-p/284960/highlight/true#M211541" target="_self"&gt;reset the password for local user&lt;/A&gt;. Also worth to see if you are using LDAP with CM.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Sep 2020 22:02:45 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Disable-remove-auto-TLS-certificates-and-create-self-signed/m-p/302638#M221201</guid>
      <dc:creator>GangWar</dc:creator>
      <dc:date>2020-09-10T22:02:45Z</dc:date>
    </item>
    <item>
      <title>Re: Disable/remove auto TLS certificates and create self signed certificate</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Disable-remove-auto-TLS-certificates-and-create-self-signed/m-p/302687#M221213</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/29629"&gt;@GangWar&lt;/a&gt;I am getting this issue while configuring the SSL for Cloudera manager. can you please help me out with this&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2020-09-11 07:03:43,787 ERROR MainThread:com.cloudera.server.cmf.config.components.BeanConfiguration: SSL init failure&lt;BR /&gt;java.io.IOException: Keystore was tampered with, or password was incorrect&lt;BR /&gt;at sun.security.provider.JavaKeyStore.engineLoad(JavaKeyStore.java:780)&lt;BR /&gt;at sun.security.provider.JavaKeyStore$JKS.engineLoad(JavaKeyStore.java:56)&lt;BR /&gt;at sun.security.provider.KeyStoreDelegator.engineLoad(KeyStoreDelegator.java:224)&lt;BR /&gt;at sun.security.provider.JavaKeyStore$DualFormatJKS.engineLoad(JavaKeyStore.java:70)&lt;BR /&gt;at java.security.KeyStore.load(KeyStore.java:1445)&lt;BR /&gt;at org.eclipse.jetty.util.security.CertificateUtils.getKeyStore(CertificateUtils.java:54)&lt;BR /&gt;at org.eclipse.jetty.util.ssl.SslContextFactory.loadTrustStore(SslContextFactory.java:1158)&lt;BR /&gt;at org.eclipse.jetty.util.ssl.SslContextFactory.load(SslContextFactory.java:315)&lt;BR /&gt;at org.eclipse.jetty.util.ssl.SslContextFactory.doStart(SslContextFactory.java:248)&lt;BR /&gt;at org.eclipse.jetty.util.component.AbstractLifeCycle.start(AbstractLifeCycle.java:68)&lt;BR /&gt;at com.cloudera.server.cmf.config.components.BeanConfiguration.getSslContextFactory(BeanConfiguration.java:126)&lt;BR /&gt;at com.cloudera.server.cmf.config.components.BeanConfiguration$$EnhancerBySpringCGLIB$$dea6ffb3.CGLIB$getSslContextFactory$3(&amp;lt;generated&amp;gt;)&lt;BR /&gt;at com.cloudera.server.cmf.config.components.BeanConfiguration$$EnhancerBySpringCGLIB$$dea6ffb3$$FastClassBySpringCGLIB$$15a496c1.invoke(&amp;lt;generated&amp;gt;)&lt;BR /&gt;at org.springframework.cglib.proxy.MethodProxy.invokeSuper(MethodProxy.java:228)&lt;BR /&gt;at org.springframework.context.annotation.ConfigurationClassEnhancer$BeanMethodInterceptor.intercept(ConfigurationClassEnhancer.java:358)&lt;BR /&gt;at com.cloudera.server.cmf.config.components.BeanConfiguration$$EnhancerBySpringCGLIB$$dea6ffb3.getSslContextFactory(&amp;lt;generated&amp;gt;)&lt;BR /&gt;at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)&lt;BR /&gt;at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62)&lt;BR /&gt;at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)&lt;BR /&gt;at java.lang.reflect.Method.invoke(Method.java:498)&lt;BR /&gt;at org.springframework.beans.factory.support.SimpleInstantiationStrategy.instantiate(SimpleInstantiationStrategy.java:162)&lt;BR /&gt;at org.springframework.beans.factory.support.ConstructorResolver.instantiateUsingFactoryMethod(ConstructorResolver.java:588)&lt;BR /&gt;at org.springframework.beans.factory.support.AbstractAutowireCapableBeanFactory.instantiateUsingFactoryMethod(AbstractAutowireCapableBeanFactory.java:1178)&lt;BR /&gt;at org.springframework.beans.factory.support.AbstractAutowireCapableBeanFactory.createBeanInstance(AbstractAutowireCapableBeanFactory.java:1072)&lt;BR /&gt;at org.springframework.beans.factory.support.AbstractAutowireCapableBeanFactory.doCreateBean(AbstractAutowireCapableBeanFactory.java:511)&lt;BR /&gt;at org.springframework.beans.factory.support.AbstractAutowireCapableBeanFactory.createBean(AbstractAutowireCapableBeanFactory.java:481)&lt;BR /&gt;at org.springframework.beans.factory.support.AbstractBeanFactory$1.getObject(AbstractBeanFactory.java:312)&lt;BR /&gt;at org.springframework.beans.factory.support.DefaultSingletonBeanRegistry.getSingleton(DefaultSingletonBeanRegistry.java:230)&lt;BR /&gt;at org.springframework.beans.factory.support.AbstractBeanFactory.doGetBean(AbstractBeanFactory.java:308)&lt;BR /&gt;at org.springframework.beans.factory.support.AbstractBeanFactory.getBean(AbstractBeanFactory.java:202)&lt;BR /&gt;at org.springframework.beans.factory.config.DependencyDescriptor.resolveCandidate(DependencyDescriptor.java:208)&lt;BR /&gt;at org.springframework.beans.factory.support.DefaultListableBeanFactory.doResolveDependency(DefaultListableBeanFactory.java:1136)&lt;BR /&gt;at org.springframework.beans.factory.support.DefaultListableBeanFactory.resolveDependency(DefaultListableBeanFactory.java:1064)&lt;BR /&gt;at org.springframework.beans.factory.support.ConstructorResolver.resolveAutowiredArgument(ConstructorResolver.java:835)&lt;BR /&gt;at org.springframework.beans.factory.support.ConstructorResolver.createArgumentArray(ConstructorResolver.java:741)&lt;BR /&gt;at org.springframework.beans.factory.support.ConstructorResolver.instantiateUsingFactoryMethod(ConstructorResolver.java:467)&lt;BR /&gt;at org.springframework.beans.factory.support.AbstractAutowireCapableBeanFactory.instantiateUsingFactoryMethod(AbstractAutowireCapableBeanFactory.java:1178)&lt;BR /&gt;at org.springframework.beans.factory.support.AbstractAutowireCapableBeanFactory.createBeanInstance(AbstractAutowireCapableBeanFactory.java:1072)&lt;BR /&gt;at org.springframework.beans.factory.support.AbstractAutowireCapableBeanFactory.doCreateBean(AbstractAutowireCapableBeanFactory.java:511)&lt;BR /&gt;at org.springframework.beans.factory.support.AbstractAutowireCapableBeanFactory.createBean(AbstractAutowireCapableBeanFactory.java:481)&lt;BR /&gt;at org.springframework.beans.factory.support.AbstractBeanFactory$1.getObject(AbstractBeanFactory.java:312)&lt;BR /&gt;at org.springframework.beans.factory.support.DefaultSingletonBeanRegistry.getSingleton(DefaultSingletonBeanRegistry.java:230)&lt;BR /&gt;at org.springframework.beans.factory.support.AbstractBeanFactory.doGetBean(AbstractBeanFactory.java:308)&lt;BR /&gt;at org.springframework.beans.factory.support.AbstractBeanFactory.getBean(AbstractBeanFactory.java:202)&lt;BR /&gt;at org.springframework.beans.factory.config.DependencyDescriptor.resolveCandidate(DependencyDescriptor.java:208)&lt;BR /&gt;at org.springframework.beans.factory.support.DefaultListableBeanFactory.doResolveDependency(DefaultListableBeanFactory.java:1136)&lt;BR /&gt;at org.springframework.beans.factory.support.DefaultListableBeanFactory.resolveDependency(DefaultListableBeanFactory.java:1064)&lt;BR /&gt;at org.springframework.beans.factory.support.ConstructorResolver.resolveAutowiredArgument(ConstructorResolver.java:835)&lt;BR /&gt;at org.springframework.beans.factory.support.ConstructorResolver.createArgumentArray(ConstructorResolver.java:741)&lt;BR /&gt;at org.springframework.beans.factory.support.ConstructorResolver.autowireConstructor(ConstructorResolver.java:189)&lt;BR /&gt;at org.springframework.beans.factory.support.AbstractAutowireCapableBeanFactory.autowireConstructor(AbstractAutowireCapableBeanFactory.java:1198)&lt;BR /&gt;at org.springframework.beans.factory.support.AbstractAutowireCapableBeanFactory.createBeanInstance(AbstractAutowireCapableBeanFactory.java:1100)&lt;BR /&gt;at org.springframework.beans.factory.support.AbstractAutowireCapableBeanFactory.doCreateBean(AbstractAutowireCapableBeanFactory.java:511)&lt;BR /&gt;at org.springframework.beans.factory.support.AbstractAutowireCapableBeanFactory.createBean(AbstractAutowireCapableBeanFactory.java:481)&lt;BR /&gt;at org.springframework.beans.factory.support.AbstractBeanFactory$1.getObject(AbstractBeanFactory.java:312)&lt;BR /&gt;at org.springframework.beans.factory.support.DefaultSingletonBeanRegistry.getSingleton(DefaultSingletonBeanRegistry.java:230)&lt;BR /&gt;at org.springframework.beans.factory.support.AbstractBeanFactory.doGetBean(AbstractBeanFactory.java:308)&lt;BR /&gt;at org.springframework.beans.factory.support.AbstractBeanFactory.getBean(AbstractBeanFactory.java:197)&lt;BR /&gt;at org.springframework.beans.factory.support.DefaultListableBeanFactory.preInstantiateSingletons(DefaultListableBeanFactory.java:761)&lt;BR /&gt;at org.springframework.context.support.AbstractApplicationContext.finishBeanFactoryInitialization(AbstractApplicationContext.java:867)&lt;BR /&gt;at org.springframework.context.support.AbstractApplicationContext.refresh(AbstractApplicationContext.java:543)&lt;BR /&gt;at org.springframework.context.support.ClassPathXmlApplicationContext.&amp;lt;init&amp;gt;(ClassPathXmlApplicationContext.java:139)&lt;BR /&gt;at org.springframework.context.support.ClassPathXmlApplicationContext.&amp;lt;init&amp;gt;(ClassPathXmlApplicationContext.java:105)&lt;BR /&gt;at sun.reflect.NativeConstructorAccessorImpl.newInstance0(Native Method)&lt;BR /&gt;at sun.reflect.NativeConstructorAccessorImpl.newInstance(NativeConstructorAccessorImpl.java:62)&lt;BR /&gt;at sun.reflect.DelegatingConstructorAccessorImpl.newInstance(DelegatingConstructorAccessorImpl.java:45)&lt;BR /&gt;at java.lang.reflect.Constructor.newInstance(Constructor.java:423)&lt;BR /&gt;at org.springframework.beans.BeanUtils.instantiateClass(BeanUtils.java:142)&lt;BR /&gt;at org.springframework.beans.factory.support.SimpleInstantiationStrategy.instantiate(SimpleInstantiationStrategy.java:122)&lt;BR /&gt;at org.springframework.beans.factory.support.ConstructorResolver.autowireConstructor(ConstructorResolver.java:271)&lt;BR /&gt;at org.springframework.beans.factory.support.AbstractAutowireCapableBeanFactory.autowireConstructor(AbstractAutowireCapableBeanFactory.java:1198)&lt;BR /&gt;at org.springframework.beans.factory.support.AbstractAutowireCapableBeanFactory.createBeanInstance(AbstractAutowireCapableBeanFactory.java:1100)&lt;BR /&gt;at org.springframework.beans.factory.support.AbstractAutowireCapableBeanFactory.doCreateBean(AbstractAutowireCapableBeanFactory.java:511)&lt;BR /&gt;at org.springframework.beans.factory.support.AbstractAutowireCapableBeanFactory.createBean(AbstractAutowireCapableBeanFactory.java:481)&lt;BR /&gt;at org.springframework.beans.factory.support.AbstractBeanFactory$1.getObject(AbstractBeanFactory.java:312)&lt;BR /&gt;at org.springframework.beans.factory.support.DefaultSingletonBeanRegistry.getSingleton(DefaultSingletonBeanRegistry.java:230)&lt;BR /&gt;at org.springframework.beans.factory.support.AbstractBeanFactory.doGetBean(AbstractBeanFactory.java:308)&lt;BR /&gt;at org.springframework.beans.factory.support.AbstractBeanFactory.getBean(AbstractBeanFactory.java:202)&lt;BR /&gt;at org.springframework.context.support.AbstractApplicationContext.getBean(AbstractApplicationContext.java:1086)&lt;BR /&gt;at org.springframework.beans.factory.access.SingletonBeanFactoryLocator.useBeanFactory(SingletonBeanFactoryLocator.java:396)&lt;BR /&gt;at com.cloudera.server.cmf.Main.findBeanFactory(Main.java:481)&lt;BR /&gt;at com.cloudera.server.cmf.Main.findRootApplicationContext(Main.java:476)&lt;BR /&gt;at com.cloudera.server.cmf.Main.&amp;lt;init&amp;gt;(Main.java:285)&lt;BR /&gt;at com.cloudera.server.cmf.Main.main(Main.java:233)&lt;BR /&gt;Caused by: java.security.UnrecoverableKeyException: Password verification failed&lt;BR /&gt;at sun.security.provider.JavaKeyStore.engineLoad(JavaKeyStore.java:778)&lt;BR /&gt;... 83 more&lt;BR /&gt;2020-09-11 07:03:43,883 INFO MainThread:com.cloudera.server.cmf.Main: Server locale set to: en&lt;BR /&gt;2020-09-11 07:03:43,894 INFO MainThread:com.cloudera.server.cmf.components.EmbeddedDbManager: CM server is NOT using embedded postgresql database for itself.&lt;BR /&gt;2020-09-11 07:03:43,901 INFO MainThread:com.cloudera.cmf.service.CommandScheduleListener: Adding command schedule listener for global-collect-host-statistics&lt;BR /&gt;2020-09-11 07:03:43,905 INFO MainThread:com.cloudera.cmf.service.CommandScheduleListener: Initializing schedule for global-collect-host-statistics&lt;BR /&gt;2020-09-11 07:03:43,907 INFO MainThread:com.cloudera.cmf.command.datacollection.ClusterStatsCommandScheduler: No license - using free bundle settings&lt;BR /&gt;2020-09-11 07:03:43,911 INFO MainThread:com.cloudera.cmf.service.CommandScheduleListener: Replacing existing schedule for global-collect-host-statistics&lt;BR /&gt;2020-09-11 07:03:43,958 INFO MainThread:com.cloudera.cmf.service.CommandScheduleListener: Removed schedule DbCommandSchedule{id=71, commandName=global-collect-host-statistics, displayName=null, description=null}&lt;BR /&gt;2020-09-11 07:03:43,960 INFO MainThread:com.cloudera.cmf.service.CommandScheduleListener: Adding schedule - DbCommandSchedule{id=72, commandName=global-collect-host-statistics, displayName=null, description=null}&lt;BR /&gt;2020-09-11 07:03:43,983 INFO MainThread:com.cloudera.cmf.scheduler.CmfScheduler: Added command schedule '72' to the scheduler&lt;BR /&gt;2020-09-11 07:03:44,047 INFO MainThread:com.cloudera.server.cmf.Main: Starting Auto Upgrade&lt;BR /&gt;2020-09-11 07:03:44,050 INFO MainThread:com.cloudera.cmf.service.upgrade.AutoUpgradeHandlerRegistry: No Auto Upgrades required.&lt;BR /&gt;2020-09-11 07:03:44,050 INFO MainThread:com.cloudera.server.cmf.Main: Successfully completed Auto Upgrade&lt;BR /&gt;2020-09-11 07:03:44,163 INFO MainThread:com.cloudera.server.cmf.Main: Agent RPC connections will use port: 7182&lt;BR /&gt;2020-09-11 07:03:44,163 INFO MainThread:com.cloudera.server.cmf.Main: Agent TLS certificates will be validated.&lt;BR /&gt;2020-09-11 07:03:44,185 INFO MainThread:com.cloudera.server.common.HttpConnectorServer: Max heartbeat processing thread: 25 and Max threads for CM agent avro http connector: 200&lt;BR /&gt;2020-09-11 07:03:44,307 INFO MainThread:com.cloudera.server.common.HttpConnectorServer: HttpConnectorServer port=7182&lt;BR /&gt;2020-09-11 07:03:44,307 INFO MainThread:com.cloudera.server.common.HttpConnectorServer: HttpConnectorServer IdleTime=300000&lt;BR /&gt;2020-09-11 07:03:44,343 INFO MainThread:org.eclipse.jetty.server.Server: jetty-9.4.14.v20181114; built: 2018-11-14T21:20:31.478Z; git: c4550056e785fb5665914545889f21dc136ad9e6; jvm 1.8.0_181-b13&lt;BR /&gt;2020-09-11 07:03:44,375 WARN MainThread:org.eclipse.jetty.security.SecurityHandler: ServletContext@o.e.j.s.ServletContextHandler@b51e1e1{/,null,STARTING} has uncovered http methods for path: /*&lt;BR /&gt;2020-09-11 07:03:44,385 INFO MainThread:org.eclipse.jetty.server.handler.ContextHandler: Started o.e.j.s.ServletContextHandler@b51e1e1{/,null,AVAILABLE}&lt;BR /&gt;2020-09-11 07:03:44,394 ERROR MainThread:com.cloudera.server.cmf.Main: Failed to start Agent listener.&lt;BR /&gt;2020-09-11 07:03:44,394 ERROR MainThread:com.cloudera.server.cmf.Main: Server failed.&lt;BR /&gt;org.apache.avro.AvroRuntimeException: java.io.IOException: Keystore was tampered with, or password was incorrect&lt;BR /&gt;at com.cloudera.server.common.HttpConnectorServer.start(HttpConnectorServer.java:224)&lt;BR /&gt;at com.cloudera.server.cmf.Main.startAgentServer(Main.java:554)&lt;BR /&gt;at com.cloudera.server.cmf.Main.run(Main.java:606)&lt;BR /&gt;at com.cloudera.server.cmf.Main.main(Main.java:234)&lt;BR /&gt;Caused by: java.io.IOException: Keystore was tampered with, or password was incorrect&lt;BR /&gt;at sun.security.provider.JavaKeyStore.engineLoad(JavaKeyStore.java:780)&lt;BR /&gt;at sun.security.provider.JavaKeyStore$JKS.engineLoad(JavaKeyStore.java:56)&lt;BR /&gt;at sun.security.provider.KeyStoreDelegator.engineLoad(KeyStoreDelegator.java:224)&lt;BR /&gt;at sun.security.provider.JavaKeyStore$DualFormatJKS.engineLoad(JavaKeyStore.java:70)&lt;BR /&gt;at java.security.KeyStore.load(KeyStore.java:1445)&lt;BR /&gt;at org.eclipse.jetty.util.security.CertificateUtils.getKeyStore(CertificateUtils.java:54)&lt;BR /&gt;at org.eclipse.jetty.util.ssl.SslContextFactory.loadTrustStore(SslContextFactory.java:1158)&lt;BR /&gt;at org.eclipse.jetty.util.ssl.SslContextFactory.load(SslContextFactory.java:315)&lt;BR /&gt;at org.eclipse.jetty.util.ssl.SslContextFactory.doStart(SslContextFactory.java:248)&lt;BR /&gt;at org.eclipse.jetty.util.component.AbstractLifeCycle.start(AbstractLifeCycle.java:68)&lt;BR /&gt;at org.eclipse.jetty.util.component.ContainerLifeCycle.start(ContainerLifeCycle.java:138)&lt;BR /&gt;at org.eclipse.jetty.util.component.ContainerLifeCycle.doStart(ContainerLifeCycle.java:117)&lt;BR /&gt;at org.eclipse.jetty.server.SslConnectionFactory.doStart(SslConnectionFactory.java:94)&lt;BR /&gt;at org.eclipse.jetty.util.component.AbstractLifeCycle.start(AbstractLifeCycle.java:68)&lt;BR /&gt;at org.eclipse.jetty.util.component.ContainerLifeCycle.start(ContainerLifeCycle.java:138)&lt;BR /&gt;at org.eclipse.jetty.util.component.ContainerLifeCycle.doStart(ContainerLifeCycle.java:117)&lt;BR /&gt;at org.eclipse.jetty.server.AbstractConnector.doStart(AbstractConnector.java:282)&lt;BR /&gt;at org.eclipse.jetty.server.AbstractNetworkConnector.doStart(AbstractNetworkConnector.java:81)&lt;BR /&gt;at org.eclipse.jetty.server.ServerConnector.doStart(ServerConnector.java:236)&lt;BR /&gt;at org.eclipse.jetty.util.component.AbstractLifeCycle.start(AbstractLifeCycle.java:68)&lt;BR /&gt;at org.eclipse.jetty.server.Server.doStart(Server.java:394)&lt;BR /&gt;at org.eclipse.jetty.util.component.AbstractLifeCycle.start(AbstractLifeCycle.java:68)&lt;BR /&gt;at com.cloudera.server.common.HttpConnectorServer.start(HttpConnectorServer.java:222)&lt;BR /&gt;... 3 more&lt;BR /&gt;Caused by: java.security.UnrecoverableKeyException: Password verification failed&lt;BR /&gt;at sun.security.provider.JavaKeyStore.engineLoad(JavaKeyStore.java:778)&lt;BR /&gt;... 25 more&lt;BR /&gt;2020-09-11 07:03:53,644 INFO ScmActive-0:com.cloudera.server.cmf.components.ScmActive: ScmActive completed successfull&lt;/P&gt;</description>
      <pubDate>Fri, 11 Sep 2020 11:05:28 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Disable-remove-auto-TLS-certificates-and-create-self-signed/m-p/302687#M221213</guid>
      <dc:creator>vaibhavm</dc:creator>
      <dc:date>2020-09-11T11:05:28Z</dc:date>
    </item>
    <item>
      <title>Re: Disable/remove auto TLS certificates and create self signed certificate</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Disable-remove-auto-TLS-certificates-and-create-self-signed/m-p/302708#M221218</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/29629"&gt;@GangWar&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/15492"&gt;@Mike in Austin&lt;/a&gt; I am generating a self signed certificate for my cluster. is it required to generate a certificate for each host(7 hosts in my cluster) or just for the Cloudera host which will be my name node?&lt;/P&gt;</description>
      <pubDate>Fri, 11 Sep 2020 13:39:58 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Disable-remove-auto-TLS-certificates-and-create-self-signed/m-p/302708#M221218</guid>
      <dc:creator>vaibhavm</dc:creator>
      <dc:date>2020-09-11T13:39:58Z</dc:date>
    </item>
    <item>
      <title>Re: Disable/remove auto TLS certificates and create self signed certificate</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Disable-remove-auto-TLS-certificates-and-create-self-signed/m-p/302756#M221233</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/29629"&gt;@GangWar&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/15492"&gt;@Mike in Austin&lt;/a&gt; What should be kept in the agentkey.pw while creating the password file?&lt;/P&gt;</description>
      <pubDate>Sat, 12 Sep 2020 10:29:52 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Disable-remove-auto-TLS-certificates-and-create-self-signed/m-p/302756#M221233</guid>
      <dc:creator>vaibhavm</dc:creator>
      <dc:date>2020-09-12T10:29:52Z</dc:date>
    </item>
    <item>
      <title>Re: Disable/remove auto TLS certificates and create self signed certificate</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Disable-remove-auto-TLS-certificates-and-create-self-signed/m-p/345989#M234717</link>
      <description>&lt;P&gt;The solution above has been the accepted answer for a long time (since CM 6.x), but the procedure is not complete, at least for Cloudera Manager 7.6 with CDP Base 7.1.6 or above.&lt;BR /&gt;After using Auto-TLS and needing to disable it because I needed to rename some nodes, I changed the &lt;STRONG&gt;web_tls&lt;/STRONG&gt; and &lt;STRONG&gt;agent_tls&lt;/STRONG&gt; settings in the Database, and changed the &lt;STRONG&gt;config.ini&lt;/STRONG&gt; to disable TLS in all the agents' config and restarted all the cloudera-scm-* daemons (server/agents) and I was able to log to the UI and reach the hosts, but in "&lt;EM&gt;Management &amp;gt;&amp;gt; Security&lt;/EM&gt;" the Cloudera Manager UI keeps showing "&lt;STRONG&gt;Auto-TLS is Enabled&lt;/STRONG&gt;" in the menu bar, and if I try to add a new host it will fail with an error like "Unable to deploy host certificates" ... so it seems CM still has Auto-TLS enable somewhere/somehow.&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="auto-tls.png" style="width: 400px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/34645i2B255C5990370AD6/image-size/medium?v=v2&amp;amp;px=400" role="button" title="auto-tls.png" alt="auto-tls.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have made a dump and double checked there isn't any TLS config parameter enabled in the DB, but there should be some other place from where CM assumes this is enabled.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2022 00:32:43 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Disable-remove-auto-TLS-certificates-and-create-self-signed/m-p/345989#M234717</guid>
      <dc:creator>lvazquez</dc:creator>
      <dc:date>2022-06-21T00:32:43Z</dc:date>
    </item>
    <item>
      <title>Re: Disable/remove auto TLS certificates and create self signed certificate</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Disable-remove-auto-TLS-certificates-and-create-self-signed/m-p/347126#M235075</link>
      <description>&lt;P&gt;Remove all TLS related config in CM UI. CM &amp;gt; Settings search for TLS and uncheck everything and delete jks files and password configs&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jul 2022 11:59:53 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Disable-remove-auto-TLS-certificates-and-create-self-signed/m-p/347126#M235075</guid>
      <dc:creator>BdE-Big</dc:creator>
      <dc:date>2022-07-08T11:59:53Z</dc:date>
    </item>
    <item>
      <title>Re: Disable/remove auto TLS certificates and create self signed certificate</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Disable-remove-auto-TLS-certificates-and-create-self-signed/m-p/347166#M235085</link>
      <description>&lt;P&gt;I thought it was something like this, but it was hard to believe!&lt;/P&gt;&lt;P&gt;After 2 full installation of CDP base, it seems clear that CDP may have been a big step for the final user, but still has a lot of room for improvement in the sysadmin and devops side of the platform, specially in the way-back or recovery of many central configuration changes (kerberos, TLS) where it really sucks, even when compared with the now ancient HDP3.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jul 2022 15:44:57 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Disable-remove-auto-TLS-certificates-and-create-self-signed/m-p/347166#M235085</guid>
      <dc:creator>lvazquez</dc:creator>
      <dc:date>2022-07-08T15:44:57Z</dc:date>
    </item>
    <item>
      <title>Re: Disable/remove auto TLS certificates and create self signed certificate</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Disable-remove-auto-TLS-certificates-and-create-self-signed/m-p/374019#M241857</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/29629"&gt;@GangWar&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is still a problem in CDP 7.1.8 where there is no possibility of turning off the "Auto-TLS is Enabled" satus in Admin --&amp;gt; Security. Has anyone found the solution? I've now combed through UI settings, db and local files for anything to do with TLS and removed most if it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know its turned off but as long as CDP thinks that Auto-TLS is ON I can't run the Auto-TLS setup Wizzard.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jul 2023 13:42:02 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Disable-remove-auto-TLS-certificates-and-create-self-signed/m-p/374019#M241857</guid>
      <dc:creator>ClouderaUser123</dc:creator>
      <dc:date>2023-07-18T13:42:02Z</dc:date>
    </item>
  </channel>
</rss>

