<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Troubleshooting CM Agent won't connect to CM Server after tls activation in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/Troubleshooting-CM-Agent-won-t-connect-to-CM-Server-after/m-p/335955#M232075</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Hi,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I am provisionning a CDP 7.1.5 cluster with CM 7.2.4&amp;nbsp; and encountered a connexion problem between the agents and cloudera manager server after tls setup through API.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;There is nothing in the server log and there is the following error in the agent log.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Could you help me understand where the problem stands ? Activating further logging or doing some tests upon the provided certificates ?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Traceback (most recent call last):&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;File "/opt/cloudera/cm-agent/lib/python2.7/site-packages/cmf/agent.py", line 1430, in _send_heartbeat&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;self.cfg.max_cert_depth)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;File "/opt/cloudera/cm-agent/lib/python2.7/site-packages/cmf/https.py", line 185, in __init__&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;self.conn.connect()&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;File "/opt/cloudera/cm-agent/lib/python2.7/site-packages/M2Crypto/httpslib.py", line 69, in connect&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;sock.connect((self.host, self.port))&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;File "/opt/cloudera/cm-agent/lib/python2.7/site-packages/M2Crypto/SSL/Connection.py", line 309, in connect&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ret = self.connect_ssl()&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;File "/opt/cloudera/cm-agent/lib/python2.7/site-packages/M2Crypto/SSL/Connection.py", line 295, in connect_ssl&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;return m2.ssl_connect(self.ssl, self._timeout)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;SSLError: sslv3 alert certificate unknown&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 10 Feb 2022 06:39:18 GMT</pubDate>
    <dc:creator>gael__urbauer</dc:creator>
    <dc:date>2022-02-10T06:39:18Z</dc:date>
    <item>
      <title>Troubleshooting CM Agent won't connect to CM Server after tls activation</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Troubleshooting-CM-Agent-won-t-connect-to-CM-Server-after/m-p/335955#M232075</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I am provisionning a CDP 7.1.5 cluster with CM 7.2.4&amp;nbsp; and encountered a connexion problem between the agents and cloudera manager server after tls setup through API.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;There is nothing in the server log and there is the following error in the agent log.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Could you help me understand where the problem stands ? Activating further logging or doing some tests upon the provided certificates ?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Traceback (most recent call last):&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;File "/opt/cloudera/cm-agent/lib/python2.7/site-packages/cmf/agent.py", line 1430, in _send_heartbeat&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;self.cfg.max_cert_depth)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;File "/opt/cloudera/cm-agent/lib/python2.7/site-packages/cmf/https.py", line 185, in __init__&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;self.conn.connect()&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;File "/opt/cloudera/cm-agent/lib/python2.7/site-packages/M2Crypto/httpslib.py", line 69, in connect&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;sock.connect((self.host, self.port))&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;File "/opt/cloudera/cm-agent/lib/python2.7/site-packages/M2Crypto/SSL/Connection.py", line 309, in connect&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ret = self.connect_ssl()&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;File "/opt/cloudera/cm-agent/lib/python2.7/site-packages/M2Crypto/SSL/Connection.py", line 295, in connect_ssl&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;return m2.ssl_connect(self.ssl, self._timeout)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;SSLError: sslv3 alert certificate unknown&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Feb 2022 06:39:18 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Troubleshooting-CM-Agent-won-t-connect-to-CM-Server-after/m-p/335955#M232075</guid>
      <dc:creator>gael__urbauer</dc:creator>
      <dc:date>2022-02-10T06:39:18Z</dc:date>
    </item>
    <item>
      <title>Re: Troubleshooting CM Agent won't connect to CM Server after tls activation</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Troubleshooting-CM-Agent-won-t-connect-to-CM-Server-after/m-p/335980#M232082</link>
      <description>&lt;P&gt;I finally solved the problem with the help of the support.&lt;/P&gt;&lt;P&gt;They redirected me to&amp;nbsp;&lt;A href="https://docs.cloudera.com/documentation/enterprise/latest/topics/how_to_configure_cm_tls.html" target="_blank"&gt;Manually Configuring TLS Encryption for Cloudera Manager | 6.3.x | Cloudera Documentation&lt;/A&gt;&lt;/P&gt;&lt;P&gt;In the section 6 I had a certificate with only the "TLS Web Server Authentication"&amp;nbsp; usage.&lt;/P&gt;&lt;P&gt;I missed the "TLS Web Client Authentication" Usage.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Feb 2022 12:59:02 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Troubleshooting-CM-Agent-won-t-connect-to-CM-Server-after/m-p/335980#M232082</guid>
      <dc:creator>gael__urbauer</dc:creator>
      <dc:date>2022-02-10T12:59:02Z</dc:date>
    </item>
  </channel>
</rss>

