<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Cloudera agent SSL error in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/Cloudera-agent-SSL-error/m-p/88333#M36444</link>
    <description>&lt;P&gt;Hi team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am trying to enable SSL in transit for my cloudera cluster using the document&amp;nbsp;&lt;A href="https://www.cloudera.com/documentation/enterprise/latest/topics/how_to_configure_cm_tls.html" target="_blank" rel="noopener"&gt;https://www.cloudera.com/documentation/enterprise/latest/topics/how_to_configure_cm_tls.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am able to successfully configure till the step "Enable Server Certificate Verification on Cloudera Manager Agents" , however once i completed "Configure Agent Certificate Authentication" , i am receiving the below error and all the hosts are in bad health state, could you please help ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[27/Mar/2019 11:12:37 +0000] 1022 MainThread agent ERROR Heartbeating to cmhost.antuit.internal:7182 failed.&lt;BR /&gt;Traceback (most recent call last):&lt;BR /&gt;File "/opt/cloudera/cm-agent/lib/python2.7/site-packages/cmf/agent.py", line 1388, in _send_heartbeat&lt;BR /&gt;self.cfg.max_cert_depth)&lt;BR /&gt;File "/opt/cloudera/cm-agent/lib/python2.7/site-packages/cmf/https.py", line 139, in __init__&lt;BR /&gt;self.conn.connect()&lt;BR /&gt;File "/opt/cloudera/cm-agent/lib/python2.7/site-packages/M2Crypto/httpslib.py", line 80, in connect&lt;BR /&gt;sock.connect((self.host, self.port))&lt;BR /&gt;File "/opt/cloudera/cm-agent/lib/python2.7/site-packages/M2Crypto/SSL/Connection.py", line 305, in connect&lt;BR /&gt;ret = self.connect_ssl()&lt;BR /&gt;File "/opt/cloudera/cm-agent/lib/python2.7/site-packages/M2Crypto/SSL/Connection.py", line 292, in connect_ssl&lt;BR /&gt;return m2.ssl_connect(self.ssl, self._timeout)&lt;BR /&gt;&lt;STRONG&gt;SSLError: sslv3 alert certificate unknown&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Notes:&lt;/P&gt;&lt;P&gt;-----&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. I am using a private intermediate CA to sign the certificates for each host.&lt;/P&gt;&lt;P&gt;2. I have imported both root and intermediate CA certs into jssecacerts in the cloudera manager host&amp;nbsp;&lt;/P&gt;&lt;P&gt;3. I am able to manually verify the signed certs&lt;/P&gt;&lt;P&gt;cat ca.cert.pem intermediate.cert.pem &amp;gt; verify.pem&lt;/P&gt;&lt;P&gt;sudo openssl verify -CAfile verifier.pem cmhost.XX.YY.pem&lt;BR /&gt;cmhost.XX.YY.pem: OK&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Chiranjeevi&lt;/P&gt;</description>
    <pubDate>Wed, 27 Mar 2019 11:30:37 GMT</pubDate>
    <dc:creator>chirunimmala</dc:creator>
    <dc:date>2019-03-27T11:30:37Z</dc:date>
  </channel>
</rss>

