<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Renew certificates on a CDP cluster that has auto tls enabled with a Root CA in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/Renew-certificates-on-a-CDP-cluster-that-has-auto-tls/m-p/390783#M247336</link>
    <description>&lt;P&gt;Hi, yes it was a problem with incorrect pass phrase being passed to the keystorePassword.&lt;/P&gt;</description>
    <pubDate>Mon, 22 Jul 2024 15:13:21 GMT</pubDate>
    <dc:creator>namteen</dc:creator>
    <dc:date>2024-07-22T15:13:21Z</dc:date>
    <item>
      <title>Renew certificates on a CDP cluster that has auto tls enabled with a Root CA</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Renew-certificates-on-a-CDP-cluster-that-has-auto-tls/m-p/390238#M247234</link>
      <description>&lt;P&gt;Hi&lt;BR /&gt;I have an existing CDP 7.1.x cluster with Auto-tls enabled during the creation of the cluster. I followed the use case 2:&amp;nbsp;&lt;A href="https://docs.cloudera.com/cdp-private-cloud-base/7.1.9/security-encrypting-data-in-transit/topics/cm-security-use-case-2.html," target="_blank" rel="noopener"&gt;https://docs.cloudera.com/cdp-private-cloud-base/7.1.9/security-encrypting-data-in-transit/topics/cm-security-use-case-2.html,&lt;/A&gt;&amp;nbsp;to use an existing Root CA. Recently the certificates expired and I'm trying to renew them. I've a couple of questions from the documentation.&lt;/P&gt;&lt;P&gt;1. In the above page, it mentions "&lt;SPAN&gt;In this use case, rotation of the Auto-TLS certificate authority is not supported. Cloudera recommends creating an intermediate CA with a long lifetime. The host certificates can be rotated by using the&amp;nbsp;&lt;/SPAN&gt;generateHostCerts&lt;SPAN&gt;&amp;nbsp;API." - Should I use this to generate the host certs. If so, can I get an example of the API call and it's usage.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;2. Or should I use this use case 3:&amp;nbsp;&lt;A href="https://docs.cloudera.com/cdp-private-cloud-base/7.1.8/security-encrypting-data-in-transit/topics/cm-security-use-case-3.html" target="_blank" rel="noopener"&gt;https://docs.cloudera.com/cdp-private-cloud-base/7.1.8/security-encrypting-data-in-transit/topics/cm-security-use-case-3.html&lt;/A&gt;. Generate the certificates myself and use the generateCmCa api?&lt;/P&gt;&lt;P&gt;I don't mind the using the UI too, but I don't think that's feasible with a different Root CA case.&amp;nbsp; Can you suggest how can I go about this please?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 21 Apr 2026 06:28:36 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Renew-certificates-on-a-CDP-cluster-that-has-auto-tls/m-p/390238#M247234</guid>
      <dc:creator>namteen</dc:creator>
      <dc:date>2026-04-21T06:28:36Z</dc:date>
    </item>
    <item>
      <title>Re: Renew certificates on a CDP cluster that has auto tls enabled with a Root CA</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Renew-certificates-on-a-CDP-cluster-that-has-auto-tls/m-p/390257#M247237</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/111574"&gt;@namteen&lt;/a&gt;&amp;nbsp;Welcome to the Cloudera Community!&lt;BR /&gt;&lt;BR /&gt;To help you get the best possible solution, I have tagged our CDP experts&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/13587"&gt;@venkatsambath&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/74887"&gt;@aakulov&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/21311"&gt;@PabitraDas&lt;/a&gt;&amp;nbsp;&amp;nbsp;who may be able to assist you further.&lt;BR /&gt;&lt;BR /&gt;Please keep us updated on your post, and we hope you find a satisfactory solution to your query.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jul 2024 18:30:35 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Renew-certificates-on-a-CDP-cluster-that-has-auto-tls/m-p/390257#M247237</guid>
      <dc:creator>DianaTorres</dc:creator>
      <dc:date>2024-07-12T18:30:35Z</dc:date>
    </item>
    <item>
      <title>Re: Renew certificates on a CDP cluster that has auto tls enabled with a Root CA</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Renew-certificates-on-a-CDP-cluster-that-has-auto-tls/m-p/390263#M247241</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/111574"&gt;@namteen&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for reaching out yes for renewing&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes you will need to use Auto-TLS use case 3&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.cloudera.com/cdp-private-cloud-base/7.1.8/security-encrypting-data-in-transit/topics/cm-security-use-case-3.html" target="_blank"&gt;https://docs.cloudera.com/cdp-private-cloud-base/7.1.8/security-encrypting-data-in-transit/topics/cm-security-use-case-3.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Also you are correct from UI you can only generate a cloudera manager signed certificate for your custom ca signed certificate you can generate the certificate yourself and pass those in generatecmca API as mentioned in use case 3&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 13 Jul 2024 08:49:49 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Renew-certificates-on-a-CDP-cluster-that-has-auto-tls/m-p/390263#M247241</guid>
      <dc:creator>upadhyayk04</dc:creator>
      <dc:date>2024-07-13T08:49:49Z</dc:date>
    </item>
    <item>
      <title>Re: Renew certificates on a CDP cluster that has auto tls enabled with a Root CA</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Renew-certificates-on-a-CDP-cluster-that-has-auto-tls/m-p/390362#M247250</link>
      <description>&lt;P&gt;Hi, I tried following the use case 3. I generated the certificates for all the hosts. When I ran the generateCmCa api, I'm running into this error:&lt;/P&gt;&lt;P&gt;Entering HTTP Operation: Method:POST, Path:/v41/cm/commands/generateCmca&lt;BR /&gt;INFO scm-web-77659:com.cloudera.cmf.service.ServiceHandlerRegistry: Executing Global command GenerateCMCACommand GenerateCmcaCmdArgs{sshPort=22, userName=REDACTED, password=REDACTED, passphrase=REDACTED, privateKey=REDACTED, customCA=true, interpretAsFilenames=true, additionalArguments=null, location=/opt/cloudera/CMCA}.&lt;BR /&gt;INFO scm-web-77659:com.cloudera.cmf.command.GenerateCmcaCommand: {CLUSTER_NAME} has Kerberos enabled and will be reconfigured to use SASL&lt;BR /&gt;INFO scm-web-77659:com.cloudera.cmf.command.flow.CmdStep: Executing command 1546436812 work: Execute 14 steps in sequence&lt;BR /&gt;INFO scm-web-77659:com.cloudera.cmf.command.flow.CmdStep: Executing command 1546436812 work: Generate a CMCA and enable Auto-TLS.&lt;BR /&gt;INFO scm-web-77659:com.cloudera.cmf.command.GenerateCmcaCmdWork: Determined CMCA location: /var/lib/cloudera-scm-server/certmanager&lt;BR /&gt;INFO scm-web-77659:com.cloudera.cmf.command.GenerateCmcaCmdWork: Modifying init file if present: /var/lib/cloudera-scm-server/certmanager/cm_init.txt&lt;BR /&gt;INFO scm-web-77659:com.cloudera.cmf.command.GenerateCmcaCmdWork: Generating CMCA&lt;BR /&gt;INFO scm-web-77659:com.cloudera.cmf.command.CertmanagerRunner: Running CMCA command with args: [setup_custom_certdir, --host-cert, REDACTED, --host-key, REDACTED, --ca-cert, REDACTED, --keystore-pw-file, /tmp/auto-tls/keys/key.pwd, --truststore-pw-file, REDACTED, --configure-services, --skip-cm-init, --override, keystore_type=jks]&lt;BR /&gt;ERROR scm-web-77659:com.cloudera.cmf.command.CertmanagerRunner: Failed to run CMCA command, return code: 1, stderr:&lt;BR /&gt;INFO:root:certmanager not running as root&lt;BR /&gt;INFO:root:Logging to /var/log/cloudera-scm-agent/certmanager.log&lt;BR /&gt;Traceback (most recent call last):&lt;BR /&gt;File "/opt/cloudera/cm-agent/bin/certmanager", line 11, in &amp;lt;module&amp;gt;&lt;BR /&gt;load_entry_point('cmf==7.6.7', 'console_scripts', 'certmanager')()&lt;BR /&gt;File "/opt/cloudera/cm-agent/lib/python2.7/site-packages/cmf/tools/cert.py", line 2857, in main&lt;BR /&gt;return certmanager(obj=argparse.Namespace())&lt;BR /&gt;File "/opt/cloudera/cm-agent/lib/python2.7/site-packages/click/core.py", line 716, in __call__&lt;BR /&gt;return self.main(*args, **kwargs)&lt;BR /&gt;File "/opt/cloudera/cm-agent/lib/python2.7/site-packages/click/core.py", line 696, in main&lt;BR /&gt;rv = self.invoke(ctx)&lt;BR /&gt;File "/opt/cloudera/cm-agent/lib/python2.7/site-packages/click/core.py", line 1060, in invoke&lt;BR /&gt;return _process_result(sub_ctx.command.invoke(sub_ctx))&lt;BR /&gt;File "/opt/cloudera/cm-agent/lib/python2.7/site-packages/click/core.py", line 889, in invoke&lt;BR /&gt;return ctx.invoke(self.callback, **ctx.params)&lt;BR /&gt;File "/opt/cloudera/cm-agent/lib/python2.7/site-packages/click/core.py", line 534, in invoke&lt;BR /&gt;return callback(*args, **kwargs)&lt;BR /&gt;File "/opt/cloudera/cm-agent/lib/python2.7/site-packages/click/decorators.py", line 27, in new_func&lt;BR /&gt;return f(get_current_context().obj, *args, **kwargs)&lt;BR /&gt;File "/opt/cloudera/cm-agent/lib/python2.7/site-packages/cmf/tools/cert.py", line 2694, in setup_custom_certdir&lt;BR /&gt;truststore_password)&lt;BR /&gt;File "/opt/cloudera/cm-agent/lib/python2.7/site-packages/cmf/tools/cert.py", line 2014, in setup_server_with_custom_certs&lt;BR /&gt;self.copy_node_cert(None, hostname)&lt;BR /&gt;File "/opt/cloudera/cm-agent/lib/python2.7/site-packages/cmf/tools/cert.py", line 1798, in copy_node_cert&lt;BR /&gt;keystore_file, hostname, password)&lt;BR /&gt;File "/opt/cloudera/cm-agent/lib/python2.7/site-packages/cmf/tools/cert.py", line 1607, in _write_keystore_file&lt;BR /&gt;raise Exception("Failed to generate host pkcs12 file.")&lt;BR /&gt;Exception: Failed to generate host pkcs12 file.&lt;/P&gt;&lt;P&gt;WARN scm-web-77659:com.cloudera.cmf.command.flow.CmdStep: Command 1546436812 Unexpected exception during doWork&lt;BR /&gt;java.lang.IllegalStateException: Failed to run CMCA command, return code: 1&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;The ssh user has root permissions assigned. Can you help me with this please&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/95611"&gt;@upadhyayk04&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2024 14:49:08 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Renew-certificates-on-a-CDP-cluster-that-has-auto-tls/m-p/390362#M247250</guid>
      <dc:creator>namteen</dc:creator>
      <dc:date>2024-07-15T14:49:08Z</dc:date>
    </item>
    <item>
      <title>Re: Renew certificates on a CDP cluster that has auto tls enabled with a Root CA</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Renew-certificates-on-a-CDP-cluster-that-has-auto-tls/m-p/390566#M247301</link>
      <description>&lt;P&gt;&lt;A href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/13587" target="_blank"&gt;@venkatsambath&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/74887" target="_blank"&gt;@aakulov&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/21311" target="_blank"&gt;@PabitraDas&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/95611"&gt;@upadhyayk04&lt;/a&gt;&amp;nbsp;Hi, do you have any insights here? Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jul 2024 17:56:59 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Renew-certificates-on-a-CDP-cluster-that-has-auto-tls/m-p/390566#M247301</guid>
      <dc:creator>DianaTorres</dc:creator>
      <dc:date>2024-07-18T17:56:59Z</dc:date>
    </item>
    <item>
      <title>Re: Renew certificates on a CDP cluster that has auto tls enabled with a Root CA</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Renew-certificates-on-a-CDP-cluster-that-has-auto-tls/m-p/390575#M247304</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/111574"&gt;@namteen&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The below error indicates there are issues with the certificates or keys. Can you please confirm if all the certificates are signed by the CM valid CA none is expired also the key and host combination that you are providing is correct&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;File "/opt/cloudera/cm-agent/lib/python2.7/site-packages/cmf/tools/cert.py", line 1607, in _write_keystore_file&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;raise Exception("Failed to generate host pkcs12 file.")&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Exception: Failed to generate host pkcs12 file.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;You can check /var/log/cloudera-scm-agent/certmanager.log on the CM server host as well to further check the error&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;gt;&amp;gt; To check whether the certificate is correct or not run the following command

# openssl x509 -in &amp;lt;cert-file&amp;gt; -noout -text

To check whether cert and key combination is correct or not match output of below commands

#openssl x509 -noout -modulus -in server.pem | openssl md5

#openssl rsa -noout -modulus -in server.key | openssl md5

where server.pem is the certificate and server.key is the key&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jul 2024 03:46:59 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Renew-certificates-on-a-CDP-cluster-that-has-auto-tls/m-p/390575#M247304</guid>
      <dc:creator>upadhyayk04</dc:creator>
      <dc:date>2024-07-19T03:46:59Z</dc:date>
    </item>
    <item>
      <title>Re: Renew certificates on a CDP cluster that has auto tls enabled with a Root CA</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Renew-certificates-on-a-CDP-cluster-that-has-auto-tls/m-p/390660#M247319</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/111574"&gt;@namteen&lt;/a&gt;&amp;nbsp;Has the reply helped resolve your issue? If so, please mark the appropriate reply as the solution, as it will make it easier for others to find the answer in the future.&amp;nbsp; Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jul 2024 20:35:30 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Renew-certificates-on-a-CDP-cluster-that-has-auto-tls/m-p/390660#M247319</guid>
      <dc:creator>DianaTorres</dc:creator>
      <dc:date>2024-07-19T20:35:30Z</dc:date>
    </item>
    <item>
      <title>Re: Renew certificates on a CDP cluster that has auto tls enabled with a Root CA</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Renew-certificates-on-a-CDP-cluster-that-has-auto-tls/m-p/390783#M247336</link>
      <description>&lt;P&gt;Hi, yes it was a problem with incorrect pass phrase being passed to the keystorePassword.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Jul 2024 15:13:21 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Renew-certificates-on-a-CDP-cluster-that-has-auto-tls/m-p/390783#M247336</guid>
      <dc:creator>namteen</dc:creator>
      <dc:date>2024-07-22T15:13:21Z</dc:date>
    </item>
  </channel>
</rss>

