<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: After enabling TLS cloudera agent heartbeat failing in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/After-enabling-TLS-cloudera-agent-heartbeat-failing/m-p/84374#M39127</link>
    <description>&lt;P&gt;&lt;SPAN&gt;This shows the client_key_file settings are fine, please also verify that the CM agent can access the files referenced as&amp;nbsp;&lt;STRONG&gt;client_key_file&lt;/STRONG&gt; and&amp;nbsp;&lt;STRONG&gt;client_key_file&lt;/STRONG&gt; in&amp;nbsp;/etc/cloudera-scm-agent/config.ini, e.g. with command&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;PRE&gt;namei -l &amp;lt;path-to-file-name&amp;gt;&lt;/PRE&gt;</description>
    <pubDate>Sat, 29 Dec 2018 13:58:57 GMT</pubDate>
    <dc:creator>gzigldrum</dc:creator>
    <dc:date>2018-12-29T13:58:57Z</dc:date>
    <item>
      <title>After enabling TLS cloudera agent heartbeat failing</title>
      <link>https://community.cloudera.com/t5/Support-Questions/After-enabling-TLS-cloudera-agent-heartbeat-failing/m-p/84337#M39124</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Version&lt;/STRONG&gt;&lt;SPAN&gt;: Cloudera Express 5.15.0&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Java VM Name&lt;/STRONG&gt;: Java HotSpot(TM) 64-Bit Server VM&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Java VM Vendor&lt;/STRONG&gt;: Oracle Corporation&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Java Version&lt;/STRONG&gt;: 1.7.0_67&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;System details:&lt;/P&gt;&lt;P&gt;Linux optim-rhel72-uppu.development.unicomglobal.software 3.10.0-327.28.3.el7.x86_64 #1 SMP Fri Aug 12 13:21:05 EDT 2016 x86_64 x86_64 x86_64 GNU/Linux&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is a single host and I am using self signed certificate. I am just validating a POC with one of my product and hence not yet licensed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Followed the steps mentioned at this link:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cloudera.com/documentation/enterprise/5-11-x/topics/how_to_configure_cm_tls.html" target="_blank"&gt;https://www.cloudera.com/documentation/enterprise/5-11-x/topics/how_to_configure_cm_tls.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cloudera.com/documentation/enterprise/5-15-x/topics/sg_self_signed_tls.html" target="_blank"&gt;https://www.cloudera.com/documentation/enterprise/5-15-x/topics/sg_self_signed_tls.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After enabling TLS, cloudera agant heartbeat is failing with the below lines in the&amp;nbsp;cloudera-scm-agent.log&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[27/Dec/2018 20:58:28 +0000] 6869 MainThread agent&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ERROR&amp;nbsp;&amp;nbsp;&amp;nbsp; Heartbeating to optim-rhel72-uppu.development.unicomglobal.software:7182 failed.&lt;BR /&gt;Traceback (most recent call last):&lt;BR /&gt;&amp;nbsp; File "/usr/lib64/cmf/agent/build/env/lib/python2.7/site-packages/cmf-5.15.0-py2.7.egg/cmf/agent.py", line 1424, in _send_heartbeat&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; self.max_cert_depth)&lt;BR /&gt;&amp;nbsp; File "/usr/lib64/cmf/agent/build/env/lib/python2.7/site-packages/cmf-5.15.0-py2.7.egg/cmf/https.py", line 138, in __init__&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; self.conn.connect()&lt;BR /&gt;&amp;nbsp; File "/usr/lib64/cmf/agent/build/env/lib/python2.7/site-packages/M2Crypto-0.24.0-py2.7-linux-x86_64.egg/M2Crypto/httpslib.py", line 59, in connect&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; sock.connect((self.host, self.port))&lt;BR /&gt;&amp;nbsp; File "/usr/lib64/cmf/agent/build/env/lib/python2.7/site-packages/M2Crypto-0.24.0-py2.7-linux-x86_64.egg/M2Crypto/SSL/Connection.py", line 195, in connect&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ret = self.connect_ssl()&lt;BR /&gt;&amp;nbsp; File "/usr/lib64/cmf/agent/build/env/lib/python2.7/site-packages/M2Crypto-0.24.0-py2.7-linux-x86_64.egg/M2Crypto/SSL/Connection.py", line 188, in connect_ssl&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; return m2.ssl_connect(self.ssl, self._timeout)&lt;BR /&gt;SSLError: unexpected eof&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;B&lt;SPAN&gt;elow lines in the&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;cloudera-scm-server.log&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2018-12-27 20:58:13,025 WARN 1320793343@agentServer-16:org.mortbay.log: javax.net.ssl.SSLHandshakeException: null cert chain&lt;BR /&gt;2018-12-27 20:58:28,034 WARN 1320793343@agentServer-16:org.mortbay.log: javax.net.ssl.SSLHandshakeException: null cert chain&lt;BR /&gt;2018-12-27 20:58:43,447 WARN 1320793343@agentServer-16:org.mortbay.log: javax.net.ssl.SSLHandshakeException: null cert chain&lt;BR /&gt;2018-12-27 20:58:58,082 WARN 1320793343@agentServer-16:org.mortbay.log: javax.net.ssl.SSLHandshakeException: null cert chain&lt;BR /&gt;2018-12-27 20:59:13,140 WARN 1320793343@agentServer-16:org.mortbay.log: javax.net.ssl.SSLHandshakeException: null cert chain&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have tried multiple times but none of them working.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I didn't find any error while running this command:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;openssl s_client -showcerts -connect optim-rhel72-uppu.development.unicomglobal.software:7182&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Any help would be highly appreciated.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Tulasi&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Dec 2018 05:09:38 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/After-enabling-TLS-cloudera-agent-heartbeat-failing/m-p/84337#M39124</guid>
      <dc:creator>Tulasi</dc:creator>
      <dc:date>2018-12-28T05:09:38Z</dc:date>
    </item>
    <item>
      <title>Re: After enabling TLS cloudera agent heartbeat failing</title>
      <link>https://community.cloudera.com/t5/Support-Questions/After-enabling-TLS-cloudera-agent-heartbeat-failing/m-p/84352#M39125</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/31292"&gt;@Tulasi&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The exception in the agent and error in CM indicate that the agent is not presenting its certificate for authentication properly.&amp;nbsp; This is often due to something being wrong regarding your&amp;nbsp;&lt;STRONG&gt;client_key_file&lt;/STRONG&gt; configuration in /etc/cloudera-scm-agent/config.ini.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you check to see what is configured with and then verify the contents and that it is a valid PEM formatted key?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can try this on the agent host to verify your agent has the right key and key password configured:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;# openssl rsa -in `grep client_key_file /etc/cloudera-scm-agent/config.ini | sed 's/client_key_file=//'` -check -passin pass:`grep client_keypw_file /etc/cloudera-scm-agent/config.ini |sed 's/client_keypw_file=//'| xargs cat`&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The output should show "RSA key ok" and the base64 encoded key text.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Dec 2018 19:46:58 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/After-enabling-TLS-cloudera-agent-heartbeat-failing/m-p/84352#M39125</guid>
      <dc:creator>bgooley</dc:creator>
      <dc:date>2018-12-28T19:46:58Z</dc:date>
    </item>
    <item>
      <title>Re: After enabling TLS cloudera agent heartbeat failing</title>
      <link>https://community.cloudera.com/t5/Support-Questions/After-enabling-TLS-cloudera-agent-heartbeat-failing/m-p/84361#M39126</link>
      <description>&lt;P&gt;Hi Bgooley,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Appreciate your quick response.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have tried what you have suggested and the output also matching, see below:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[root@optim-rhel72-uppu security]# openssl rsa -in `grep client_key_file /etc/cloudera-scm-agent/config.ini | sed 's/client_key_file=//'` -check -passin pass:`grep client_keypw_file /etc/cloudera-scm-agent/config.ini |sed 's/client_keypw_file=//'| xargs cat`&lt;BR /&gt;RSA key ok&lt;BR /&gt;writing RSA key&lt;BR /&gt;-----BEGIN RSA PRIVATE KEY-----&lt;BR /&gt;MIIEpAIBAAKCAQEA5BoT3b00kTdMvhv9UO2Na3//1n+HNcD9nxH4ZVW/Ye2HeY+3&lt;/P&gt;&lt;P&gt;&amp;lt;&amp;lt;&amp;lt;&amp;lt; other lines&amp;gt;&amp;gt;&amp;gt;&amp;gt;&lt;/P&gt;&lt;P&gt;C5bNRh3+6bdksCaDFXB85cm96iZfmbZIO4oks5fomkuvBpPa3izjAQ==&lt;BR /&gt;-----END RSA PRIVATE KEY-----&lt;/P&gt;&lt;P&gt;[root@optim-rhel72-uppu security]#&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let me know if you need anything else.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tulasi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 29 Dec 2018 03:59:56 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/After-enabling-TLS-cloudera-agent-heartbeat-failing/m-p/84361#M39126</guid>
      <dc:creator>Tulasi</dc:creator>
      <dc:date>2018-12-29T03:59:56Z</dc:date>
    </item>
    <item>
      <title>Re: After enabling TLS cloudera agent heartbeat failing</title>
      <link>https://community.cloudera.com/t5/Support-Questions/After-enabling-TLS-cloudera-agent-heartbeat-failing/m-p/84374#M39127</link>
      <description>&lt;P&gt;&lt;SPAN&gt;This shows the client_key_file settings are fine, please also verify that the CM agent can access the files referenced as&amp;nbsp;&lt;STRONG&gt;client_key_file&lt;/STRONG&gt; and&amp;nbsp;&lt;STRONG&gt;client_key_file&lt;/STRONG&gt; in&amp;nbsp;/etc/cloudera-scm-agent/config.ini, e.g. with command&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;PRE&gt;namei -l &amp;lt;path-to-file-name&amp;gt;&lt;/PRE&gt;</description>
      <pubDate>Sat, 29 Dec 2018 13:58:57 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/After-enabling-TLS-cloudera-agent-heartbeat-failing/m-p/84374#M39127</guid>
      <dc:creator>gzigldrum</dc:creator>
      <dc:date>2018-12-29T13:58:57Z</dc:date>
    </item>
    <item>
      <title>Re: After enabling TLS cloudera agent heartbeat failing</title>
      <link>https://community.cloudera.com/t5/Support-Questions/After-enabling-TLS-cloudera-agent-heartbeat-failing/m-p/84376#M39128</link>
      <description>&lt;P&gt;This is what I see:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[root@optim-rhel72-uppu ~]# namei -l /opt/cloudera/security/pki&lt;BR /&gt;f: /opt/cloudera/security/pki&lt;BR /&gt;dr-xr-xr-x root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; /&lt;BR /&gt;drwxr-xr-x root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; opt&lt;BR /&gt;drwxr-xr-x cloudera-scm cloudera-scm cloudera&lt;BR /&gt;drwxr-xr-x cloudera-scm cloudera-scm security&lt;BR /&gt;drwxr-xr-x cloudera-scm cloudera-scm pki&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;[root@optim-rhel72-uppu ~]# namei -l&amp;nbsp; /etc/cloudera-scm-agent&lt;BR /&gt;f: /etc/cloudera-scm-agent&lt;BR /&gt;dr-xr-xr-x root root /&lt;BR /&gt;drwxr-xr-x root root etc&lt;BR /&gt;drwxr-xr-x root root cloudera-scm-agent&lt;/P&gt;</description>
      <pubDate>Sat, 29 Dec 2018 14:10:08 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/After-enabling-TLS-cloudera-agent-heartbeat-failing/m-p/84376#M39128</guid>
      <dc:creator>Tulasi</dc:creator>
      <dc:date>2018-12-29T14:10:08Z</dc:date>
    </item>
    <item>
      <title>Re: After enabling TLS cloudera agent heartbeat failing</title>
      <link>https://community.cloudera.com/t5/Support-Questions/After-enabling-TLS-cloudera-agent-heartbeat-failing/m-p/84377#M39129</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Sorry for being unclear but the command needs to have the full path including the actual filename as specified in config.ini for client_key_file and client_keypw_file&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 29 Dec 2018 15:35:10 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/After-enabling-TLS-cloudera-agent-heartbeat-failing/m-p/84377#M39129</guid>
      <dc:creator>gzigldrum</dc:creator>
      <dc:date>2018-12-29T15:35:10Z</dc:date>
    </item>
    <item>
      <title>Re: After enabling TLS cloudera agent heartbeat failing</title>
      <link>https://community.cloudera.com/t5/Support-Questions/After-enabling-TLS-cloudera-agent-heartbeat-failing/m-p/84378#M39130</link>
      <description>&lt;P&gt;Thanks for looking at it, here is the output and let me know if anything else is required.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[root@optim-rhel72-uppu ~]# namei -l /opt/cloudera/security/pki/agent.key&lt;BR /&gt;f: /opt/cloudera/security/pki/agent.key&lt;BR /&gt;dr-xr-xr-x root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; /&lt;BR /&gt;drwxr-xr-x root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; root&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; opt&lt;BR /&gt;drwxr-xr-x cloudera-scm cloudera-scm cloudera&lt;BR /&gt;drwxr-xr-x cloudera-scm cloudera-scm security&lt;BR /&gt;drwxr-xr-x cloudera-scm cloudera-scm pki&lt;BR /&gt;lrwxrwxrwx cloudera-scm cloudera-scm agent.key -&amp;gt; optim-rhel72-uppu.key&lt;BR /&gt;-rw-r--r-- cloudera-scm cloudera-scm&amp;nbsp;&amp;nbsp; optim-rhel72-uppu.key&lt;BR /&gt;[root@optim-rhel72-uppu ~]# namei -l /etc/cloudera-scm-agent/agentkey.pw&lt;BR /&gt;f: /etc/cloudera-scm-agent/agentkey.pw&lt;BR /&gt;dr-xr-xr-x root root /&lt;BR /&gt;drwxr-xr-x root root etc&lt;BR /&gt;drwxr-xr-x root root cloudera-scm-agent&lt;BR /&gt;-rw-r--r-- root root agentkey.pw&lt;/P&gt;</description>
      <pubDate>Sat, 29 Dec 2018 16:14:08 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/After-enabling-TLS-cloudera-agent-heartbeat-failing/m-p/84378#M39130</guid>
      <dc:creator>Tulasi</dc:creator>
      <dc:date>2018-12-29T16:14:08Z</dc:date>
    </item>
    <item>
      <title>Re: After enabling TLS cloudera agent heartbeat failing</title>
      <link>https://community.cloudera.com/t5/Support-Questions/After-enabling-TLS-cloudera-agent-heartbeat-failing/m-p/84548#M39131</link>
      <description>&lt;P&gt;It is still not solved, any inputs would be appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tulasi&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jan 2019 09:05:28 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/After-enabling-TLS-cloudera-agent-heartbeat-failing/m-p/84548#M39131</guid>
      <dc:creator>Tulasi</dc:creator>
      <dc:date>2019-01-04T09:05:28Z</dc:date>
    </item>
    <item>
      <title>Re: After enabling TLS cloudera agent heartbeat failing</title>
      <link>https://community.cloudera.com/t5/Support-Questions/After-enabling-TLS-cloudera-agent-heartbeat-failing/m-p/84644#M39132</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are sorry you are still encountering this issue. Since we know that the problem is isolated to TLS and that the agent is reporting a null certificate chain you will need to isolate why the certificate chain is null.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1.) Ensure that the certificates are in a standard x509 format for the agent.&lt;/P&gt;&lt;P&gt;2.) Ensure that the truststores/keystores on the CM host are in JCEKS format and not pkcs12.&lt;/P&gt;&lt;P&gt;3.) Make sure that the &lt;EM&gt;cloudera-scm&lt;/EM&gt; user can read the Private Key, Certificates, Truststores, and Password Files.&lt;/P&gt;&lt;P&gt;4.) Make sure that the certificate on the failing agent contains a proper CN and DNS Alt Name if Alt Names are in use.&lt;/P&gt;&lt;P&gt;5.)&amp;nbsp;Are you using self-signed certificates or certificates signed by a CA?&lt;/P&gt;&lt;P&gt;6.) If all else fails you can obtain a tcpdump of attempted communication with the server. The port that we normally heartbeat to is 7182. You can then review the conversation between the server and agent to attempt to identify at what point the error is returned and potentially what error is being observed at the protocol level. You can identify and restrict your tcpdump information by tcp.stream.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Jan 2019 16:39:23 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/After-enabling-TLS-cloudera-agent-heartbeat-failing/m-p/84644#M39132</guid>
      <dc:creator>lhebert</dc:creator>
      <dc:date>2019-01-08T16:39:23Z</dc:date>
    </item>
    <item>
      <title>Re: After enabling TLS cloudera agent heartbeat failing</title>
      <link>https://community.cloudera.com/t5/Support-Questions/After-enabling-TLS-cloudera-agent-heartbeat-failing/m-p/84890#M39133</link>
      <description>Hi, Thanks for the response, I see one difference (in point 2) between document what you have noted. Document says to use PKCS12 format but you are suggesting JCEKS format. I didn't try with JCEKS, could you please confirm which format is correct. 2.) Ensure that the truststores/keystores on the CM host are in JCEKS format and not pkcs12. Document link &lt;A href="https://www.cloudera.com/documentation/enterprise/5-15-x/topics/how_to_configure_cm_tls.html" target="_blank"&gt;https://www.cloudera.com/documentation/enterprise/5-15-x/topics/how_to_configure_cm_tls.html&lt;/A&gt; Thanks, Tulasi</description>
      <pubDate>Mon, 14 Jan 2019 09:05:46 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/After-enabling-TLS-cloudera-agent-heartbeat-failing/m-p/84890#M39133</guid>
      <dc:creator>Tulasi</dc:creator>
      <dc:date>2019-01-14T09:05:46Z</dc:date>
    </item>
    <item>
      <title>Re: After enabling TLS cloudera agent heartbeat failing</title>
      <link>https://community.cloudera.com/t5/Support-Questions/After-enabling-TLS-cloudera-agent-heartbeat-failing/m-p/84893#M39134</link>
      <description>Please note that keystores/truststores need to be in standard JCEKS format and the documentation does not state otherwise. PKCS12 is only used for exporting and converting certificate plus private key to PEM format for CM agent config. Can you please point to the sentence suggesting PKCS12 format so that we can correct it?</description>
      <pubDate>Mon, 14 Jan 2019 09:19:27 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/After-enabling-TLS-cloudera-agent-heartbeat-failing/m-p/84893#M39134</guid>
      <dc:creator>gzigldrum</dc:creator>
      <dc:date>2019-01-14T09:19:27Z</dc:date>
    </item>
    <item>
      <title>Re: After enabling TLS cloudera agent heartbeat failing</title>
      <link>https://community.cloudera.com/t5/Support-Questions/After-enabling-TLS-cloudera-agent-heartbeat-failing/m-p/84924#M39135</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is my response to your questions, can you please correct me what I am doing wrong. Also if you need some more details, I should be able to share.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tulasi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1.) Ensure that the certificates are in a standard x509 format for the agent.&lt;BR /&gt;Yes it is standard x509, see my response to Bgooley&lt;BR /&gt;&lt;BR /&gt;2.) Ensure that the truststores/keystores on the CM host are in JCEKS format and not pkcs12.&lt;BR /&gt;As per cloudera document, it should be JCEKS. From the link &amp;nbsp;&lt;BR /&gt;&lt;A href="https://www.cloudera.com/documentation/enterprise/5-15-x/topics/how_to_configure_cm_tls.html" target="_blank"&gt;https://www.cloudera.com/documentation/enterprise/5-15-x/topics/how_to_configure_cm_tls.html&lt;/A&gt;&lt;BR /&gt;section "Generate TLS Certificate", point 3&lt;BR /&gt;&lt;BR /&gt;3.) Make sure that the cloudera-scm user can read the Private Key, Certificates, Truststores, and Password Files.&lt;BR /&gt;Yes, see my response to gzigldrum&lt;BR /&gt;&lt;BR /&gt;4.) Make sure that the certificate on the failing agent contains a proper CN and DNS Alt Name if Alt Names are in use.&lt;BR /&gt;Yes, I have verified this as well&lt;BR /&gt;&lt;BR /&gt;5.) Are you using self-signed certificates or certificates signed by a CA?&lt;BR /&gt;I am using self signed certificate&lt;BR /&gt;&lt;BR /&gt;6.) If all else fails you can obtain a tcpdump of attempted communication with the server. The port that we normally heartbeat to is 7182. You can then review the conversation between the server and agent to attempt to identify at what point the error is returned and potentially what error is being observed at the protocol level. You can identify and restrict your tcpdump information by tcp.stream.&lt;BR /&gt;&lt;BR /&gt;[root@optim-rhel72-uppu ~]# tcpdump -i any 'port 7182'&lt;BR /&gt;tcpdump: verbose output suppressed, use -v or -vv for full protocol decode&lt;BR /&gt;listening on any, link-type LINUX_SLL (Linux cooked), capture size 65535 bytes&lt;BR /&gt;21:20:03.562131 IP optim-rhel72-uppu.development.unicomglobal.software.44942 &amp;gt; optim-rhel72-uppu.development.unicomglobal.software.7182: Flags [S], seq 3560294529, win 43690, options [mss 65495,sackOK,TS val 1632415805 ecr 0,nop,wscale 7], length 0&lt;BR /&gt;21:20:03.562225 IP optim-rhel72-uppu.development.unicomglobal.software.44942 &amp;gt; optim-rhel72-uppu.development.unicomglobal.software.7182: Flags [.], ack 1, win 342, options [nop,nop,TS val 1632415805 ecr 1632415805], length 0&lt;BR /&gt;21:20:03.562549 IP optim-rhel72-uppu.development.unicomglobal.software.44942 &amp;gt; optim-rhel72-uppu.development.unicomglobal.software.7182: Flags [P.], seq 1:254, ack 1, win 342, options [nop,nop,TS val 1632415806 ecr 1632415805], length 253&lt;BR /&gt;21:20:03.587871 IP optim-rhel72-uppu.development.unicomglobal.software.44942 &amp;gt; optim-rhel72-uppu.development.unicomglobal.software.7182: Flags [.], ack 16390, win 1365, options [nop,nop,TS val 1632415831 ecr 1632415831], length 0&lt;BR /&gt;21:20:03.587919 IP optim-rhel72-uppu.development.unicomglobal.software.44942 &amp;gt; optim-rhel72-uppu.development.unicomglobal.software.7182: Flags [.], ack 21184, win 2388, options [nop,nop,TS val 1632415831 ecr 1632415831], length 0&lt;BR /&gt;21:20:03.619895 IP optim-rhel72-uppu.development.unicomglobal.software.44942 &amp;gt; optim-rhel72-uppu.development.unicomglobal.software.7182: Flags [P.], seq 254:516, ack 21184, win 2388, options [nop,nop,TS val 1632415863 ecr 1632415831], length 262&lt;BR /&gt;21:20:03.628945 IP optim-rhel72-uppu.development.unicomglobal.software.44942 &amp;gt; optim-rhel72-uppu.development.unicomglobal.software.7182: Flags [F.], seq 516, ack 21185, win 2388, options [nop,nop,TS val 1632415872 ecr 1632415864], length 0&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jan 2019 05:24:41 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/After-enabling-TLS-cloudera-agent-heartbeat-failing/m-p/84924#M39135</guid>
      <dc:creator>Tulasi</dc:creator>
      <dc:date>2019-01-15T05:24:41Z</dc:date>
    </item>
    <item>
      <title>Re: After enabling TLS cloudera agent heartbeat failing</title>
      <link>https://community.cloudera.com/t5/Support-Questions/After-enabling-TLS-cloudera-agent-heartbeat-failing/m-p/84980#M39136</link>
      <description>&lt;P&gt;In addition to that, can you please show us the CM agent configuration with&lt;/P&gt;&lt;PRE&gt;# egrep -v '^[[:blank:]]*#|^$' /etc/cloudera-scm-agent/config.ini&lt;/PRE&gt;</description>
      <pubDate>Wed, 16 Jan 2019 11:18:14 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/After-enabling-TLS-cloudera-agent-heartbeat-failing/m-p/84980#M39136</guid>
      <dc:creator>gzigldrum</dc:creator>
      <dc:date>2019-01-16T11:18:14Z</dc:date>
    </item>
    <item>
      <title>Re: After enabling TLS cloudera agent heartbeat failing</title>
      <link>https://community.cloudera.com/t5/Support-Questions/After-enabling-TLS-cloudera-agent-heartbeat-failing/m-p/84991#M39137</link>
      <description>&lt;P&gt;Here is the output:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[root@optim-rhel72-uppu ~]# egrep -v '^[[:blank:]]*#|^$' /etc/cloudera-scm-agent/config.ini&lt;BR /&gt;[General]&lt;BR /&gt;server_host=optim-rhel72-uppu.development.unicomglobal.software&lt;BR /&gt;server_port=7182&lt;BR /&gt;max_collection_wait_seconds=10.0&lt;BR /&gt;metrics_url_timeout_seconds=30.0&lt;BR /&gt;task_metrics_timeout_seconds=5.0&lt;BR /&gt;monitored_nodev_filesystem_types=nfs,nfs4,tmpfs&lt;BR /&gt;local_filesystem_whitelist=ext2,ext3,ext4,xfs&lt;BR /&gt;impala_profile_bundle_max_bytes=1073741824&lt;BR /&gt;stacks_log_bundle_max_bytes=1073741824&lt;BR /&gt;stacks_log_max_uncompressed_file_size_bytes=5242880&lt;BR /&gt;orphan_process_dir_staleness_threshold=5184000&lt;BR /&gt;orphan_process_dir_refresh_interval=3600&lt;BR /&gt;scm_debug=INFO&lt;BR /&gt;dns_resolution_collection_interval_seconds=60&lt;BR /&gt;dns_resolution_collection_timeout_seconds=30&lt;BR /&gt;[Security]&lt;BR /&gt;use_tls=1&lt;BR /&gt;max_cert_depth=9&lt;BR /&gt;&amp;nbsp;verify_cert_file=/opt/cloudera/security/pki/optim-rhel72-uppu.pem&lt;BR /&gt;&amp;nbsp;verify_cert_dir=/opt/cloudera/security/pki&lt;BR /&gt;&amp;nbsp;client_key_file=/opt/cloudera/security/pki/agent.key&lt;BR /&gt;&amp;nbsp;client_keypw_file=/etc/cloudera-scm-agent/agentkey.pw&lt;BR /&gt;&amp;nbsp;client_cert_file=/opt/cloudera/security/pki/agent.pem&lt;BR /&gt;[Hadoop]&lt;BR /&gt;[Cloudera]&lt;BR /&gt;[JDBC]&lt;BR /&gt;[root@optim-rhel72-uppu ~]#&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jan 2019 16:33:59 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/After-enabling-TLS-cloudera-agent-heartbeat-failing/m-p/84991#M39137</guid>
      <dc:creator>Tulasi</dc:creator>
      <dc:date>2019-01-16T16:33:59Z</dc:date>
    </item>
    <item>
      <title>Re: After enabling TLS cloudera agent heartbeat failing</title>
      <link>https://community.cloudera.com/t5/Support-Questions/After-enabling-TLS-cloudera-agent-heartbeat-failing/m-p/85005#M39138</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/31292"&gt;@Tulasi&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for providing your config.&amp;nbsp; It appears you have space characters at the beginning of your cert/key configs.&amp;nbsp; Remove the space characters form the beginning of the following lines and then restart the agent:&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;&amp;nbsp;verify_cert_file=/opt/cloudera/security/pki/optim-rhel72-uppu.pem&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;&amp;nbsp;verify_cert_dir=/opt/cloudera/security/pki&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;&amp;nbsp;client_key_file=/opt/cloudera/security/pki/agent.key&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;&amp;nbsp;client_keypw_file=/etc/cloudera-scm-agent/agentkey.pw&lt;/SPAN&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&lt;SPAN&gt;&amp;nbsp;client_cert_file=/opt/cloudera/security/pki/agent.pem&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jan 2019 21:42:45 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/After-enabling-TLS-cloudera-agent-heartbeat-failing/m-p/85005#M39138</guid>
      <dc:creator>bgooley</dc:creator>
      <dc:date>2019-01-16T21:42:45Z</dc:date>
    </item>
    <item>
      <title>Re: After enabling TLS cloudera agent heartbeat failing</title>
      <link>https://community.cloudera.com/t5/Support-Questions/After-enabling-TLS-cloudera-agent-heartbeat-failing/m-p/85007#M39139</link>
      <description>&lt;P&gt;NOTE:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You should only specify verify_cert_dir OR verify_cert_file, not both&lt;/P&gt;&lt;P&gt;Since you have a pem file, I would suggest using verify_cert_file and commenting out "&lt;SPAN&gt;verify_cert_dir=/opt/cloudera/security/pki"&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jan 2019 21:46:50 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/After-enabling-TLS-cloudera-agent-heartbeat-failing/m-p/85007#M39139</guid>
      <dc:creator>bgooley</dc:creator>
      <dc:date>2019-01-16T21:46:50Z</dc:date>
    </item>
    <item>
      <title>Re: After enabling TLS cloudera agent heartbeat failing</title>
      <link>https://community.cloudera.com/t5/Support-Questions/After-enabling-TLS-cloudera-agent-heartbeat-failing/m-p/85093#M39140</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/4054"&gt;@bgooley&lt;/a&gt;,&amp;nbsp;&lt;/P&gt;&lt;P&gt;space characters at the bginning of cert/key in the agent configuration file is created this problem. After removing all of those spaces, restarted agent worked.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I didn't expect a space can create this sort of problem without telling what is going wrong.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for helping to figure this silly problem.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jan 2019 04:22:47 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/After-enabling-TLS-cloudera-agent-heartbeat-failing/m-p/85093#M39140</guid>
      <dc:creator>Tulasi</dc:creator>
      <dc:date>2019-01-18T04:22:47Z</dc:date>
    </item>
    <item>
      <title>Re: After enabling TLS cloudera agent heartbeat failing</title>
      <link>https://community.cloudera.com/t5/Support-Questions/After-enabling-TLS-cloudera-agent-heartbeat-failing/m-p/85111#M39141</link>
      <description>&lt;P&gt;I have followed the steps under "&lt;SPAN&gt;Configuring TLS/SSL for HDFS, YARN and MapReduce&lt;/SPAN&gt;"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Service did not start successfully; not all of the required roles started: only 0/1 roles started. Reasons : Service has only 0 NodeManager roles running instead of minimum required 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;YARN failing to start and I see below error in the log&lt;/P&gt;&lt;P&gt;Can't open /run/cloudera-scm-agent/process/190-yarn-NODEMANAGER/container-executor.cfg: Permission denied&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is the permission:&lt;/P&gt;&lt;P&gt;-rw-r----- 1 yarn hadoop&amp;nbsp;&amp;nbsp; 997 Jan 18 02:22 creds.localjceks&lt;BR /&gt;-rw------- 1 yarn hadoop&amp;nbsp; 1746 Jan 18 02:22 yarn.keytab&lt;BR /&gt;-r-------- 1 root hadoop&amp;nbsp;&amp;nbsp; 156 Jan 18 02:22 container-executor.cfg&lt;BR /&gt;-rw------- 1 root root&amp;nbsp;&amp;nbsp;&amp;nbsp; 3688 Jan 18 02:22 supervisor.conf&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But after giving permission, restart creates another foldr with the same permission, how to resolve this problem.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tulasi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jan 2019 10:25:49 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/After-enabling-TLS-cloudera-agent-heartbeat-failing/m-p/85111#M39141</guid>
      <dc:creator>Tulasi</dc:creator>
      <dc:date>2019-01-18T10:25:49Z</dc:date>
    </item>
    <item>
      <title>Re: After enabling TLS cloudera agent heartbeat failing</title>
      <link>https://community.cloudera.com/t5/Support-Questions/After-enabling-TLS-cloudera-agent-heartbeat-failing/m-p/85372#M39142</link>
      <description>&lt;P&gt;I opened a Jira internally at Cloudera to ask that config.ini leading non-word characters be trimmed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ben&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jan 2019 21:47:18 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/After-enabling-TLS-cloudera-agent-heartbeat-failing/m-p/85372#M39142</guid>
      <dc:creator>bgooley</dc:creator>
      <dc:date>2019-01-23T21:47:18Z</dc:date>
    </item>
    <item>
      <title>Re: After enabling TLS cloudera agent heartbeat failing</title>
      <link>https://community.cloudera.com/t5/Support-Questions/After-enabling-TLS-cloudera-agent-heartbeat-failing/m-p/85373#M39143</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/31292"&gt;@Tulasi&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you start a new thread with your new issue so that we don't mix issues in the same thread.&amp;nbsp; the space character issue is likely to help others, so it would be good to start a new thread for permission denied issue.&amp;nbsp; I think it is a known one, but it will be easier to discuss if we can start fresh.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jan 2019 21:48:57 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/After-enabling-TLS-cloudera-agent-heartbeat-failing/m-p/85373#M39143</guid>
      <dc:creator>bgooley</dc:creator>
      <dc:date>2019-01-23T21:48:57Z</dc:date>
    </item>
  </channel>
</rss>

