<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Hive Kerberos with SSL - how to configure in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/Hive-Kerberos-with-SSL-how-to-configure/m-p/363511#M239008</link>
    <description>&lt;P&gt;&lt;SPAN&gt;I followed&amp;nbsp;&lt;/SPAN&gt;&lt;A class="editor-rtfLink" href="https://docs.cloudera.com/cdp-private-cloud-base/7.1.8/securing-hive/topics/hive-enable-tls.html" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;https://docs.cloudera.com/cdp-private-cloud-base/7.1.8/securing-hive/topics/hive-enable-tls.html&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;to configure Hive Kerberos with SSL. There was no issue, however , when I tried to obtain/display certs on client side to be used in connection, I obtained the following:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;openssl s_client -connect my_host:10000 -showcerts&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;CONNECTED(00000005)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;read:errno=0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;---&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;no peer certificate available&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;---&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;No client certificate CA names sent&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;---&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;SSL handshake has read 0 bytes and written 287 bytes&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;---&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;New, (NONE), Cipher is (NONE)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Secure Renegotiation IS NOT supported&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Compression: NONE&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Expansion: NONE&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;No ALPN negotiated&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;SSL-Session:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp;Protocol : TLSv1.3&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp;Cipher : 0000&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp;Session-ID:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp;Session-ID-ctx:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp;Master-Key:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp;Start Time: 1675956752&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp;Timeout : 7200 (sec)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp;Verify return code: 0 (ok)&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 09 Feb 2023 15:36:32 GMT</pubDate>
    <dc:creator>ArtG001</dc:creator>
    <dc:date>2023-02-09T15:36:32Z</dc:date>
    <item>
      <title>Hive Kerberos with SSL - how to configure</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Hive-Kerberos-with-SSL-how-to-configure/m-p/363511#M239008</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I followed&amp;nbsp;&lt;/SPAN&gt;&lt;A class="editor-rtfLink" href="https://docs.cloudera.com/cdp-private-cloud-base/7.1.8/securing-hive/topics/hive-enable-tls.html" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;https://docs.cloudera.com/cdp-private-cloud-base/7.1.8/securing-hive/topics/hive-enable-tls.html&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;to configure Hive Kerberos with SSL. There was no issue, however , when I tried to obtain/display certs on client side to be used in connection, I obtained the following:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;openssl s_client -connect my_host:10000 -showcerts&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;CONNECTED(00000005)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;read:errno=0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;---&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;no peer certificate available&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;---&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;No client certificate CA names sent&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;---&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;SSL handshake has read 0 bytes and written 287 bytes&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;---&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;New, (NONE), Cipher is (NONE)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Secure Renegotiation IS NOT supported&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Compression: NONE&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Expansion: NONE&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;No ALPN negotiated&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;SSL-Session:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp;Protocol : TLSv1.3&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp;Cipher : 0000&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp;Session-ID:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp;Session-ID-ctx:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp;Master-Key:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp;Start Time: 1675956752&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp;Timeout : 7200 (sec)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp;&amp;nbsp;Verify return code: 0 (ok)&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Feb 2023 15:36:32 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Hive-Kerberos-with-SSL-how-to-configure/m-p/363511#M239008</guid>
      <dc:creator>ArtG001</dc:creator>
      <dc:date>2023-02-09T15:36:32Z</dc:date>
    </item>
    <item>
      <title>Re: Hive Kerberos with SSL - how to configure</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Hive-Kerberos-with-SSL-how-to-configure/m-p/364799#M239238</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/103413"&gt;@ArtG001&lt;/a&gt;&amp;nbsp;Have you enabled SSL/TLS for Hiveserver2 as per the doc you have shared above, else we should see a valid result here? Do confirm.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried the openssl command on a non SSL Hive endpoint and I got similar response.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Feb 2023 10:07:22 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Hive-Kerberos-with-SSL-how-to-configure/m-p/364799#M239238</guid>
      <dc:creator>smruti</dc:creator>
      <dc:date>2023-02-28T10:07:22Z</dc:date>
    </item>
  </channel>
</rss>

