<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Cloudera agent SSL error in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/Cloudera-agent-SSL-error/m-p/88359#M36446</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes i have completed the steps in "Enable server certificate verification" . Please find details below,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note: The verifier.pem file has both RootCA and IntermediateCA certificates and cmhost.antuit.internal.pem has the signed certificate + IntermediateCA certificate&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;# A file of CA certificates in PEM format. The file can contain several CA&lt;BR /&gt;# certificates identified by&lt;BR /&gt;#&lt;BR /&gt;# -----BEGIN CERTIFICATE-----&lt;BR /&gt;# ... (CA certificate in base64 encoding) ...&lt;BR /&gt;# -----END CERTIFICATE-----&lt;BR /&gt;#&lt;BR /&gt;# sequences. Before, between, and after the certificates text is allowed which&lt;BR /&gt;# can be used e.g. for descriptions of the certificates.&lt;BR /&gt;#&lt;BR /&gt;# The file is loaded once, the first time an HTTPS connection is attempted. A&lt;BR /&gt;# restart of the agent is required to pick up changes to the file.&lt;BR /&gt;#&lt;BR /&gt;# Note that if neither verify_cert_file or verify_cert_dir is set, certificate&lt;BR /&gt;# verification will not be performed.&lt;BR /&gt;&lt;STRONG&gt;verify_cert_file=/opt/cloudera/security/pki/verifier.pem&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;[root@cmhost pki]# openssl s_client -connect cmhost.antuit.internal:7182 -CAfile verifier.pem -cert cmhost.antuit.internal.pem -key agent.key&lt;/STRONG&gt;&lt;BR /&gt;Enter pass phrase for agent.key:&lt;BR /&gt;CONNECTED(00000003)&lt;BR /&gt;depth=2 C = IN, ST = KA, L = BNG, O = Antuit, OU = DE, CN = Antuit Root CA&lt;BR /&gt;verify return:1&lt;BR /&gt;depth=1 C = IN, ST = KA, O = Antuit, OU = DE, CN = Antuit Inter CA&lt;BR /&gt;verify return:1&lt;BR /&gt;depth=0 C = IN, ST = KA, L = BNG, O = Antuit, OU = DE, CN = cmhost.antuit.internal&lt;BR /&gt;verify return:1&lt;BR /&gt;&lt;STRONG&gt;140606215886736:error:14094416:SSL routines:ssl3_read_bytes:sslv3 alert certificate unknown:s3_pkt.c:1493:SSL alert number 46&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;140606215886736:error:140790E5:SSL routines:ssl23_write:ssl handshake failure:s23_lib.c:177:&lt;/STRONG&gt;&lt;BR /&gt;---&lt;BR /&gt;Certificate chain&lt;BR /&gt;0 s:/C=IN/ST=KA/L=BNG/O=Antuit/OU=DE/CN=cmhost.antuit.internal&lt;BR /&gt;i:/C=IN/ST=KA/O=Antuit/OU=DE/CN=Antuit Inter CA&lt;BR /&gt;1 s:/C=IN/ST=KA/O=Antuit/OU=DE/CN=Antuit Inter CA&lt;BR /&gt;i:/C=IN/ST=KA/L=BNG/O=Antuit/OU=DE/CN=Antuit Root CA&lt;BR /&gt;---&lt;/P&gt;</description>
    <pubDate>Thu, 28 Mar 2019 04:27:39 GMT</pubDate>
    <dc:creator>chirunimmala</dc:creator>
    <dc:date>2019-03-28T04:27:39Z</dc:date>
  </channel>
</rss>

