<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Testing HSM connection falied in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/Testing-HSM-connection-falied/m-p/412729#M253655</link>
    <description>&lt;P&gt;Update:&lt;/P&gt;&lt;P&gt;# curl -k -v &lt;A href="http://localhost:9090/test_hsm" target="_blank"&gt;http://localhost:9090/test_hsm&lt;/A&gt;&lt;BR /&gt;* Trying ::1...&lt;BR /&gt;* TCP_NODELAY set&lt;BR /&gt;* Connected to localhost (::1) port 9090 (#0)&lt;BR /&gt;&amp;gt; GET /test_hsm HTTP/1.1&lt;BR /&gt;&amp;gt; Host: localhost:9090&lt;BR /&gt;&amp;gt; User-Agent: curl/7.61.1&lt;BR /&gt;&amp;gt; Accept: */*&lt;BR /&gt;&amp;gt;&lt;BR /&gt;Warning: Binary output can mess up your terminal. Use "--output -" to tell&lt;BR /&gt;Warning: curl to output it to your terminal anyway, or consider "--output&lt;BR /&gt;Warning: &amp;lt;FILE&amp;gt;" to save to a file.&lt;BR /&gt;* Failed writing body (0 != 7)&lt;BR /&gt;* Closing connection 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 23 Oct 2025 21:48:40 GMT</pubDate>
    <dc:creator>Dalier</dc:creator>
    <dc:date>2025-10-23T21:48:40Z</dc:date>
    <item>
      <title>Testing HSM connection falied</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Testing-HSM-connection-falied/m-p/412726#M253652</link>
      <description>&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;I have configured the HSM.&lt;/P&gt;&lt;P&gt;However, testing per &lt;A href="https://docs.cloudera.com/cdp-private-cloud-base/7.1.8/security-navigator-key-hsm/topics/cm-security-navigator-key-hsm-validate.html" target="_blank" rel="noopener"&gt;Validating Key HSM Settings&lt;/A&gt; fails.&lt;/P&gt;&lt;P&gt;Settings&lt;BR /&gt;----------&lt;/P&gt;&lt;P&gt;# sudo service keyhsm settings&lt;/P&gt;&lt;P&gt;keyHsm Server Configuration information:&lt;BR /&gt;&lt;EM&gt;keyhsm.management.address : 127.0.0.1&lt;BR /&gt;&lt;/EM&gt;&lt;EM&gt;keyhsm.server.port : 9090&lt;BR /&gt;&lt;/EM&gt;&lt;EM&gt;keyhsm.management.port : 9899&lt;BR /&gt;&lt;/EM&gt;&lt;EM&gt;keyhsm.service.port : 19791&lt;BR /&gt;&lt;/EM&gt;&lt;EM&gt;keyhsm.jvm.heap.mx.gb : 2&lt;BR /&gt;&lt;/EM&gt;&lt;EM&gt;keyhsm.hardware : ncipher&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Module OCS Password&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;thales.ocs_password : V6DvCGbrimcD7UPA6QnoOhJb37mFOuoScY30LfWjDwvCybL4E99eT5SKUOcZdu6pq5y66iROKZboNagXzCRxl4x7+N3C3ypKzUJV5UwV3hBjaNS2/qpbyUQD+UUgCoOkm6CxuiOFbOu9CmhnlHBC2UwxqjtnMrtzCR7XMI/Vegm6iZGwR9YWFSeTRRjPkQ/Rhce81hTIqmk7U0+LGHEK+niuARmVt6EG7nmDvZMQufqhOoG2yd4FlYKv2Lv9dDKEKTByv/xoT+/Qh/+Y+8ZbuZHDbEPPzJrq6K848jXhV2wBGTt4RJeKayBzUjwix2LREonTcOctgDf/oJhuIbS2dA==&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Status&lt;BR /&gt;--------&lt;/P&gt;&lt;P&gt;&lt;EM&gt;[root@cloudera-manager ~]# sudo service keyhsm status&lt;BR /&gt;&lt;/EM&gt;&lt;EM&gt;Key HSM is running as of Thursday October 23rd, 2025 (10:32 AM), (Started : Thursday October 23rd, 2025 (10:29 AM))&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Validation failed&lt;BR /&gt;&amp;nbsp;--------------------&lt;/P&gt;&lt;P&gt;What is port 11371?&lt;/P&gt;&lt;P&gt;&lt;EM&gt;# curl -k &lt;A href="https://localhost:11371/test_hsm" target="_blank" rel="noopener"&gt;https://localhost:11371/test_hsm&lt;/A&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;EM&gt;curl: (7) Failed to connect to localhost port 11371: Connection refused&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Shouldn’t it be 9090, or 19791?&lt;/P&gt;&lt;P&gt;&lt;EM&gt;# curl -k &lt;A href="https://localhost:9090/test_hsm" target="_blank" rel="noopener"&gt;https://localhost:9090/test_hsm&lt;/A&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;EM&gt;curl: (35) error:14094412:SSL routines:ssl3_read_bytes:sslv3 alert bad certificate&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;# curl -k &lt;A href="https://localhost:19791/test_hsm" target="_blank" rel="noopener"&gt;https://localhost:19791/test_hsm&lt;/A&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;EM&gt;curl: (7) Failed to connect to localhost port 19791: Connection refused&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;I completed &lt;A href="https://docs.cloudera.com/cdp-private-cloud-base/7.1.8/security-encrypting-data-in-transit/topics/cm-security-how-to-configure-cm-tls.html" target="_blank" rel="noopener"&gt;Generate TLS Certificates&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;Dalier.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Oct 2025 16:14:50 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Testing-HSM-connection-falied/m-p/412726#M253652</guid>
      <dc:creator>Dalier</dc:creator>
      <dc:date>2025-10-23T16:14:50Z</dc:date>
    </item>
    <item>
      <title>Re: Testing HSM connection falied</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Testing-HSM-connection-falied/m-p/412729#M253655</link>
      <description>&lt;P&gt;Update:&lt;/P&gt;&lt;P&gt;# curl -k -v &lt;A href="http://localhost:9090/test_hsm" target="_blank"&gt;http://localhost:9090/test_hsm&lt;/A&gt;&lt;BR /&gt;* Trying ::1...&lt;BR /&gt;* TCP_NODELAY set&lt;BR /&gt;* Connected to localhost (::1) port 9090 (#0)&lt;BR /&gt;&amp;gt; GET /test_hsm HTTP/1.1&lt;BR /&gt;&amp;gt; Host: localhost:9090&lt;BR /&gt;&amp;gt; User-Agent: curl/7.61.1&lt;BR /&gt;&amp;gt; Accept: */*&lt;BR /&gt;&amp;gt;&lt;BR /&gt;Warning: Binary output can mess up your terminal. Use "--output -" to tell&lt;BR /&gt;Warning: curl to output it to your terminal anyway, or consider "--output&lt;BR /&gt;Warning: &amp;lt;FILE&amp;gt;" to save to a file.&lt;BR /&gt;* Failed writing body (0 != 7)&lt;BR /&gt;* Closing connection 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Oct 2025 21:48:40 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Testing-HSM-connection-falied/m-p/412729#M253655</guid>
      <dc:creator>Dalier</dc:creator>
      <dc:date>2025-10-23T21:48:40Z</dc:date>
    </item>
  </channel>
</rss>

