<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Ambari server 2.1.0: How to enable TLSv1.2 for the ports 8440 and 8441? in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ambari-server-2-1-0-How-to-enable-TLSv1-2-for-the-ports-8440/m-p/98909#M12151</link>
    <description>&lt;P&gt;&lt;A href="https://community.hortonworks.com/questions/6093/ambari-server-210-how-to-enable-tlsv12-for-the-por.html#"&gt;@Andy LoPresto&lt;/A&gt;:
 It's not that I'm trying to open multiple HTTPS connections. Ports 8440
 and 8441 are used by the Ambari server for secure (HTTPS) communication
 with the agents in the cluster, see &lt;A href="https://ambari.apache.org/1.2.5/installing-hadoop-using-ambari/content/reference_chap2_7.html"&gt;here&lt;/A&gt;. My question is how to enable TLSv1.2 transport for these two secure connections.&lt;/P&gt;</description>
    <pubDate>Mon, 14 Dec 2015 20:31:15 GMT</pubDate>
    <dc:creator>ppedemonte</dc:creator>
    <dc:date>2015-12-14T20:31:15Z</dc:date>
    <item>
      <title>Ambari server 2.1.0: How to enable TLSv1.2 for the ports 8440 and 8441?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ambari-server-2-1-0-How-to-enable-TLSv1-2-for-the-ports-8440/m-p/98907#M12149</link>
      <description>&lt;P&gt;Our stringent security policies require using TLSv1.2 for connections supporting SSL/TLS traffic. Since ports 8440 and 8441 use HTTPS, I need to enable TLSv1.2 for both. I couldn't find anything in the documentation suggesting that it's possible to configure the underlying SSL protocol used by secure connections. Is this kind of setup supported by Ambari v2.1.0?&lt;/P&gt;</description>
      <pubDate>Sat, 12 Dec 2015 03:03:34 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ambari-server-2-1-0-How-to-enable-TLSv1-2-for-the-ports-8440/m-p/98907#M12149</guid>
      <dc:creator>ppedemonte</dc:creator>
      <dc:date>2015-12-12T03:03:34Z</dc:date>
    </item>
    <item>
      <title>Re: Ambari server 2.1.0: How to enable TLSv1.2 for the ports 8440 and 8441?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ambari-server-2-1-0-How-to-enable-TLSv1-2-for-the-ports-8440/m-p/98908#M12150</link>
      <description>&lt;P&gt;Pablo, you use both ports for TLS traffic? Default HTTPS is 8443, but to change the port, you can refer to &lt;A target="_blank" href="https://ambari.apache.org/1.2.5/installing-hadoop-using-ambari/content/ambari-chap2-2a.html"&gt;this document&lt;/A&gt; from v 1.2.5. I am not sure if Ambari is able to open multiple ports for HTTPS simultaneously. &lt;/P&gt;</description>
      <pubDate>Sun, 13 Dec 2015 06:46:56 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ambari-server-2-1-0-How-to-enable-TLSv1-2-for-the-ports-8440/m-p/98908#M12150</guid>
      <dc:creator>alopresto</dc:creator>
      <dc:date>2015-12-13T06:46:56Z</dc:date>
    </item>
    <item>
      <title>Re: Ambari server 2.1.0: How to enable TLSv1.2 for the ports 8440 and 8441?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ambari-server-2-1-0-How-to-enable-TLSv1-2-for-the-ports-8440/m-p/98909#M12151</link>
      <description>&lt;P&gt;&lt;A href="https://community.hortonworks.com/questions/6093/ambari-server-210-how-to-enable-tlsv12-for-the-por.html#"&gt;@Andy LoPresto&lt;/A&gt;:
 It's not that I'm trying to open multiple HTTPS connections. Ports 8440
 and 8441 are used by the Ambari server for secure (HTTPS) communication
 with the agents in the cluster, see &lt;A href="https://ambari.apache.org/1.2.5/installing-hadoop-using-ambari/content/reference_chap2_7.html"&gt;here&lt;/A&gt;. My question is how to enable TLSv1.2 transport for these two secure connections.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Dec 2015 20:31:15 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ambari-server-2-1-0-How-to-enable-TLSv1-2-for-the-ports-8440/m-p/98909#M12151</guid>
      <dc:creator>ppedemonte</dc:creator>
      <dc:date>2015-12-14T20:31:15Z</dc:date>
    </item>
    <item>
      <title>Re: Ambari server 2.1.0: How to enable TLSv1.2 for the ports 8440 and 8441?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ambari-server-2-1-0-How-to-enable-TLSv1-2-for-the-ports-8440/m-p/98910#M12152</link>
      <description>&lt;P&gt;
	To configure the cipher suites used for Ambari server, you can use the following settings in 
	&lt;CODE&gt;ambari.properties&lt;/CODE&gt;. Even though it is not listed in the example below, you should be able to provide &lt;CODE&gt;TLSv1&lt;/CODE&gt; and &lt;CODE&gt;TLSv1.1&lt;/CODE&gt; as an option to disable it and allow only &lt;CODE&gt;TLSv1.2&lt;/CODE&gt; to be used.
&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
Ambari provides control of ciphers and protocols that are exposed via Ambari Server.
	&lt;OL&gt;
		&lt;LI&gt;To disable specific ciphers, you can optionally add a list of the following format to ambari.properties. If you specify multiple ciphers, separate each cipher using a vertical bar |.
		&lt;CODE&gt;security.server.disabled.ciphers=TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA&lt;/CODE&gt;&lt;/LI&gt;
		&lt;LI&gt;To disable specific protocols, you can optionally add a list of the following format to ambari.properties. If you specify multiple protocols, separate each protocol using a vertical bar |.
		&lt;CODE&gt;security.server.disabled.protocols=SSL|SSLv2|SSLv3&lt;/CODE&gt;&lt;/LI&gt;
	&lt;/OL&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;
	See section 3.8 of the 
	&lt;A target="_blank" href="http://docs.hortonworks.com/HDPDocuments/Ambari-2.1.0.0/bk_Ambari_Security_Guide/bk_Ambari_Security_Guide-20150721.pdf"&gt;Hortonworks Data Platform Ambari Security Guide. &lt;/A&gt;
&lt;/P&gt;</description>
      <pubDate>Tue, 15 Dec 2015 02:36:33 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ambari-server-2-1-0-How-to-enable-TLSv1-2-for-the-ports-8440/m-p/98910#M12152</guid>
      <dc:creator>alopresto</dc:creator>
      <dc:date>2015-12-15T02:36:33Z</dc:date>
    </item>
    <item>
      <title>Re: Ambari server 2.1.0: How to enable TLSv1.2 for the ports 8440 and 8441?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ambari-server-2-1-0-How-to-enable-TLSv1-2-for-the-ports-8440/m-p/98911#M12153</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/1306/ppedemonte.html" nodeid="1306"&gt;@Pablo Pedemonte&lt;/A&gt; Sorry, I misunderstood your question. I've added an answer below. &lt;/P&gt;</description>
      <pubDate>Tue, 15 Dec 2015 02:37:09 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ambari-server-2-1-0-How-to-enable-TLSv1-2-for-the-ports-8440/m-p/98911#M12153</guid>
      <dc:creator>alopresto</dc:creator>
      <dc:date>2015-12-15T02:37:09Z</dc:date>
    </item>
    <item>
      <title>Re: Ambari server 2.1.0: How to enable TLSv1.2 for the ports 8440 and 8441?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ambari-server-2-1-0-How-to-enable-TLSv1-2-for-the-ports-8440/m-p/98912#M12154</link>
      <description>&lt;P&gt;
	Thanks Andy.&lt;/P&gt;&lt;P&gt;
Indeed a setting of the form &lt;CODE&gt;security.server.disabled.protocols=SSL|SSLv2|SSLv3|TLSv1|TLSv1.1&lt;/CODE&gt; disables all the unwanted protocols. But this cuts all the communication with the nodes, since for some reason &lt;CODE&gt;TLSv1.2&lt;/CODE&gt; isn't active by default and there's no option to enable protocols. So I ended up creating my own Ambari fork, where I explicitly enable &lt;CODE&gt;TLSv1.2&lt;/CODE&gt; in the source code. Then, disabling the &lt;CODE&gt;SSL&lt;/CODE&gt; family and the old &lt;CODE&gt;TLS&lt;/CODE&gt; protocols leaves only &lt;CODE&gt;TLSv1.2&lt;/CODE&gt; as intended.&lt;/P&gt;&lt;P&gt;Problem solved.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Dec 2015 22:38:30 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ambari-server-2-1-0-How-to-enable-TLSv1-2-for-the-ports-8440/m-p/98912#M12154</guid>
      <dc:creator>ppedemonte</dc:creator>
      <dc:date>2015-12-17T22:38:30Z</dc:date>
    </item>
    <item>
      <title>Re: Ambari server 2.1.0: How to enable TLSv1.2 for the ports 8440 and 8441?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ambari-server-2-1-0-How-to-enable-TLSv1-2-for-the-ports-8440/m-p/98913#M12155</link>
      <description>&lt;P&gt;Thanks Pablo. I'm not an Ambari expert so I didn't realize TLS v1.2 was not enabled by default. I checked the Ambari issue tracker and they don't seem to have an issue for this yet, so I'm sure they would appreciate you &lt;A target="_blank" href="https://issues.apache.org/jira/browse/AMBARI/?selectedTab=com.atlassian.jira.jira-projects-plugin:summary-panel"&gt;submitting a ticket&lt;/A&gt; and including your patch.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Dec 2015 01:22:04 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ambari-server-2-1-0-How-to-enable-TLSv1-2-for-the-ports-8440/m-p/98913#M12155</guid>
      <dc:creator>alopresto</dc:creator>
      <dc:date>2015-12-18T01:22:04Z</dc:date>
    </item>
    <item>
      <title>Re: Ambari server 2.1.0: How to enable TLSv1.2 for the ports 8440 and 8441?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ambari-server-2-1-0-How-to-enable-TLSv1-2-for-the-ports-8440/m-p/98914#M12156</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/1306/ppedemonte.html" nodeid="1306"&gt;@Pablo Pedemonte&lt;/A&gt; &lt;A rel="user" href="https://community.cloudera.com/users/595/alopresto.html" nodeid="595"&gt;@Andy LoPresto&lt;/A&gt; this was addressed in Ambari 2.4.2 per &lt;A href="https://issues.apache.org/jira/browse/AMBARI-18910" target="_blank"&gt;https://issues.apache.org/jira/browse/AMBARI-18910&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2017 05:16:30 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ambari-server-2-1-0-How-to-enable-TLSv1-2-for-the-ports-8440/m-p/98914#M12156</guid>
      <dc:creator>slachterman</dc:creator>
      <dc:date>2017-03-23T05:16:30Z</dc:date>
    </item>
    <item>
      <title>Re: Ambari server 2.1.0: How to enable TLSv1.2 for the ports 8440 and 8441?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ambari-server-2-1-0-How-to-enable-TLSv1-2-for-the-ports-8440/m-p/98915#M12157</link>
      <description>&lt;P&gt;Any reason why Ambari still enables SSLv2 and SSLv3 by default? Those were considered insecure 7+ years ago. Since Feb 2014, all modern browsers have supported TLSv1.2. &lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2017 05:31:35 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ambari-server-2-1-0-How-to-enable-TLSv1-2-for-the-ports-8440/m-p/98915#M12157</guid>
      <dc:creator>alopresto</dc:creator>
      <dc:date>2017-03-23T05:31:35Z</dc:date>
    </item>
  </channel>
</rss>

