<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Impala JDBC client fails to connect to  kerberized &amp;amp; ssl enabled cluster in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/Impala-JDBC-client-fails-to-connect-to-kerberized-amp-ssl/m-p/320080#M228095</link>
    <description>&lt;P&gt;Thanks for the confirmation&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/89337"&gt;@rodrigo_fritsch&lt;/a&gt;. I have marked your reply as the solution.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 08 Jul 2021 04:27:53 GMT</pubDate>
    <dc:creator>VidyaSargur</dc:creator>
    <dc:date>2021-07-08T04:27:53Z</dc:date>
    <item>
      <title>Impala JDBC client fails to connect to  kerberized &amp; ssl enabled cluster</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Impala-JDBC-client-fails-to-connect-to-kerberized-amp-ssl/m-p/86949#M12014</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are not able to connect to impala from squirrel /workbench&amp;nbsp;client using JDBC.&lt;/P&gt;
&lt;P&gt;At the same time, We are able to successfully connect using ODBC driver.&lt;/P&gt;
&lt;P&gt;There is no configuration issue from Kerberos side as we are able to fetch the data using ODBC.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have installed&lt;/P&gt;
&lt;P&gt;1) CDH 6.1 cluster&lt;/P&gt;
&lt;P&gt;2) MIT Kerberos enabled&lt;/P&gt;
&lt;P&gt;3) SSL enabled for Impala&lt;/P&gt;
&lt;P&gt;4) T&lt;SPAN&gt;ested using the Impala JDBC driver version 2.5.45(ClouderaImpalaJDBC4_2.5.45) &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;and 2.6.2 (impala_jdbc_2.6.2.1003)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are getting the below error&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;[Simba][ImpalaJDBCDriver](500164) Error initialized or created transport for authentication: [Simba][ImpalaJDBCDriver](500169) Unable to connect to server: GSS initiate failed&lt;BR /&gt;Also, could not send response: org.apache.thrift.transport.TTransportException: javax.net.ssl.SSLHandshakeException: sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Connection strings:&lt;/P&gt;
&lt;P&gt;jdbc:impala://Loadbalancer.amazonaws.com:21050/default;AuthMech=1;KrbHostFQDN=master2-impala-146.com;KrbRealm=PRODIMPALA.COM;KrbServiceName=impala;SSL=1;CAIssuedCertNamesMismatch=1;SocketTimeout=10;loglevel=6;logpath=d:\;TrustedCerts=D:\CA-Certs\\cacerts&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;jdbc:impala://&lt;SPAN&gt;Loadbalancer.amazonaws.com:21050&lt;/SPAN&gt;/default;AuthMech=1;KrbHostFQDN=master2-impala-146;KrbRealm=PRODIMPALA.COM;KrbServiceName=impala;ssl=1;CAIssuedCertNamesMismatch=1;loglevel=6;logpath=d:\CA-CERTS\;TrustedCerts="C:\Program Files (x86)\Java\jre1.8.0_201\lib\security\cacerts"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;jdbc:impala://&lt;/SPAN&gt;&lt;SPAN&gt;Loadbalancer.amazonaws.com:21050&lt;/SPAN&gt;&lt;SPAN&gt;/default;AuthMech=1;KrbHostFQDN=master2-impala-146;KrbRealm=PRODIMPALA.COM;KrbServiceName=impala;ssl=1;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Different Options:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1) Imported the pem file into /jre/lib/security/cacerts&lt;/P&gt;
&lt;P&gt;2) Copied the jssecacerts from impala node to client node&lt;/P&gt;
&lt;P&gt;3) Tried connecting with jks&amp;nbsp;file&lt;/P&gt;
&lt;P&gt;4)&amp;nbsp;Tried with both impala jdbc 4 &amp;amp; 4.1 driver.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any help would be really appreciated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Balaji&lt;/P&gt;</description>
      <pubDate>Fri, 16 Sep 2022 14:11:34 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Impala-JDBC-client-fails-to-connect-to-kerberized-amp-ssl/m-p/86949#M12014</guid>
      <dc:creator>lnarayan</dc:creator>
      <dc:date>2022-09-16T14:11:34Z</dc:date>
    </item>
    <item>
      <title>Re: Impala JDBC client fails to connect to  kerberized &amp; ssl enabled cluster</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Impala-JDBC-client-fails-to-connect-to-kerberized-amp-ssl/m-p/89410#M12015</link>
      <description>&lt;P&gt;I am having the same problem, were you able to resolve this ? If so can you share your e&lt;SPAN&gt;xperience&lt;/SPAN&gt; ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2019 00:16:09 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Impala-JDBC-client-fails-to-connect-to-kerberized-amp-ssl/m-p/89410#M12015</guid>
      <dc:creator>anirudh</dc:creator>
      <dc:date>2019-04-23T00:16:09Z</dc:date>
    </item>
    <item>
      <title>Re: Impala JDBC client fails to connect to  kerberized &amp; ssl enabled cluster</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Impala-JDBC-client-fails-to-connect-to-kerberized-amp-ssl/m-p/318036#M227391</link>
      <description>&lt;P&gt;Hi Guys.&lt;/P&gt;&lt;P&gt;Well, we had the same problem here and at the end, we identified there something in the network blocking the certificate validation. It was the OpenDns and we solved it by adding the server to the whitelist.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jun 2021 18:22:24 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Impala-JDBC-client-fails-to-connect-to-kerberized-amp-ssl/m-p/318036#M227391</guid>
      <dc:creator>rodrigo_fritsch</dc:creator>
      <dc:date>2021-06-09T18:22:24Z</dc:date>
    </item>
    <item>
      <title>Re: Impala JDBC client fails to connect to  kerberized &amp; ssl enabled cluster</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Impala-JDBC-client-fails-to-connect-to-kerberized-amp-ssl/m-p/318756#M227529</link>
      <description>&lt;P&gt;Hello Balaji&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Could you confirm if you are using the same certificates for both the JDBC and ODBC connection strings?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. The error looks like more of cert DNS issue&amp;nbsp;&lt;SPAN&gt;un.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;hat application if it can trust it. The way trust is handled in the Java world is that you have a keystore (typically&amp;nbsp;$JAVA_HOME/lib/security/cacerts), also known as the truststore.&amp;nbsp;This contains a list of all known Certificate Authority (CA) certificates, and Java will only trust certificates that are signed by one of those CAs or public certificates that exist within that&amp;nbsp;keystore. For example, if we look at the certificate for Atlassian, we can see that the&amp;nbsp;&lt;STRONG&gt;*.atlassian.com&lt;/STRONG&gt;&amp;nbsp;certificate has been signed by the intermediate certificates,&amp;nbsp;&lt;STRONG&gt;DigiCert High Assurance EV Root CA&lt;/STRONG&gt;&amp;nbsp;and&amp;nbsp;&lt;STRONG&gt;DigiCert&amp;nbsp;High Assurance CA-3&lt;/STRONG&gt;.&amp;nbsp;These intermediate certificates have been signed by the root&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&lt;/STRONG&gt;&lt;A href="http://entrust.net/" target="_blank" rel="noopener"&gt;&lt;SPAN class="s1"&gt;&lt;STRONG&gt;Entrust.net&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;STRONG&gt;&amp;nbsp;Secure Server CA&amp;nbsp;&lt;/STRONG&gt;:&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;These three certificates combined are referred to as the certificate chain, and, as they are all within the Java keystore (cacerts), Java will trust any certificates signed by them (in this c&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;This problem is therefore caused by a certificate that is self-signed (a CA did not sign it) or a certificate chain that does not exist within the Java truststore. Java does not trust the certificate and fails to connect to the application.&lt;/P&gt;&lt;P class="p2"&gt;&lt;STRONG&gt;Resolution&lt;/STRONG&gt;&lt;/P&gt;&lt;OL class="ol1"&gt;&lt;LI&gt;Make sure you have imported the public certificate of the target instance into the truststore..&lt;/LI&gt;&lt;LI&gt;&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Make sure any certificates have been imported into the correct truststore; you may have multiple JRE/JDKs. See&amp;nbsp;&lt;A href="https://confluence.atlassian.com/jira/installing-java-185729673.html" target="_blank" rel="noopener"&gt;&lt;SPAN class="s1"&gt;Installing Java&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;for this.&lt;/LI&gt;&lt;LI&gt;Check to see that the correct truststore is in use. If&amp;nbsp;-&lt;A href="http://djavax.net/" target="_blank" rel="noopener"&gt;&lt;SPAN class="s1"&gt;Djavax.net&lt;/SPAN&gt;&lt;/A&gt;.ssl.trustStore&amp;nbsp;has been configured, it will override the location of the default truststore, which will need to be checked.&lt;/LI&gt;&lt;LI&gt;If this error results while integrating with an LDAP server over LDAPS and there is more than one LDAP server, .&amp;nbsp; Optionally, import the SSL certificates from the other LDAP servers into the&amp;nbsp;Confluence truststore.&lt;/LI&gt;&lt;LI&gt;Check if your Anti Virus tool has "SSL Scanning" blocking SSL/TLS. If it does, disable this feature or set exceptions for the target addresses (check the product documentation to see if this is possible.)&lt;/LI&gt;&lt;LI&gt;If connecting to a mail server, such as Exchange, ensure authentication allows plain text.&lt;/LI&gt;&lt;LI&gt;Verify that the target server is configured to serve SSL correctly. This can be done with the&amp;nbsp;&lt;A href="https://www.ssllabs.com/ssltest/" target="_blank" rel="noopener"&gt;&lt;SPAN class="s1"&gt;SSL Server Test&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;tool.&lt;/LI&gt;&lt;LI&gt;If all else fails, your truststore might be out of date. Upgrade Java to the latest version supported by your application.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jun 2021 06:17:46 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Impala-JDBC-client-fails-to-connect-to-kerberized-amp-ssl/m-p/318756#M227529</guid>
      <dc:creator>saini saab</dc:creator>
      <dc:date>2021-06-16T06:17:46Z</dc:date>
    </item>
    <item>
      <title>Re: Impala JDBC client fails to connect to  kerberized &amp; ssl enabled cluster</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Impala-JDBC-client-fails-to-connect-to-kerberized-amp-ssl/m-p/319031#M227650</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/89337"&gt;@rodrigo_fritsch&lt;/a&gt;,&amp;nbsp;Has the reply helped resolve your issue? If so, please mark the appropriate reply as the solution, as it will make it easier for others to find the answer in the future.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jun 2021 05:09:49 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Impala-JDBC-client-fails-to-connect-to-kerberized-amp-ssl/m-p/319031#M227650</guid>
      <dc:creator>VidyaSargur</dc:creator>
      <dc:date>2021-06-21T05:09:49Z</dc:date>
    </item>
    <item>
      <title>Re: Impala JDBC client fails to connect to  kerberized &amp; ssl enabled cluster</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Impala-JDBC-client-fails-to-connect-to-kerberized-amp-ssl/m-p/319977#M228069</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/89337"&gt;@rodrigo_fritsch&lt;/a&gt;, would you have any update on the solutions provided? If they have helped you resolve the issue, can you kindly accept the appropriate response as a solution?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jul 2021 06:52:31 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Impala-JDBC-client-fails-to-connect-to-kerberized-amp-ssl/m-p/319977#M228069</guid>
      <dc:creator>VidyaSargur</dc:creator>
      <dc:date>2021-07-07T06:52:31Z</dc:date>
    </item>
    <item>
      <title>Re: Impala JDBC client fails to connect to  kerberized &amp; ssl enabled cluster</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Impala-JDBC-client-fails-to-connect-to-kerberized-amp-ssl/m-p/319997#M228076</link>
      <description>&lt;P&gt;Hi VydiaSargur!&lt;/P&gt;&lt;P&gt;Maybe I didn't express myself well. I have replied to the topic to help the other people, we had the same problem here and fortunately, we were able to fix it by adding the CDP server to the DNS's whitelist.&lt;BR /&gt;Anyway, thank you for your answer. It was complete and surely will be much useful than mine to help other users.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jul 2021 12:18:32 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Impala-JDBC-client-fails-to-connect-to-kerberized-amp-ssl/m-p/319997#M228076</guid>
      <dc:creator>rodrigo_fritsch</dc:creator>
      <dc:date>2021-07-07T12:18:32Z</dc:date>
    </item>
    <item>
      <title>Re: Impala JDBC client fails to connect to  kerberized &amp; ssl enabled cluster</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Impala-JDBC-client-fails-to-connect-to-kerberized-amp-ssl/m-p/320080#M228095</link>
      <description>&lt;P&gt;Thanks for the confirmation&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/89337"&gt;@rodrigo_fritsch&lt;/a&gt;. I have marked your reply as the solution.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jul 2021 04:27:53 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Impala-JDBC-client-fails-to-connect-to-kerberized-amp-ssl/m-p/320080#M228095</guid>
      <dc:creator>VidyaSargur</dc:creator>
      <dc:date>2021-07-08T04:27:53Z</dc:date>
    </item>
  </channel>
</rss>

