<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question HDFS rest encryption zone unable to find valid certification path in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/HDFS-rest-encryption-zone-unable-to-find-valid-certification/m-p/39157#M23993</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cluster having the rest encryption enabled, I am able to create keys using "#hdfs key create mykey1" but not able to create encryption&amp;nbsp;zone on hdfs&amp;nbsp;directories.&lt;/P&gt;&lt;P&gt;Please find below steps for reference&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-bash-4.1$ hadoop key list&lt;BR /&gt;Listing keys for KeyProvider: KMSClientProvider[&lt;A href="https://fqdn:16000/kms/v1/" target="_blank"&gt;https://fqdn:16000/kms/v1/&lt;/A&gt;]&lt;BR /&gt;mykey2&lt;BR /&gt;mykey1&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I got below error when I am going to assign encryption zone to hdfs empty dir.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-sh-4.1$ hdfs crypto -createZone -keyName&amp;nbsp; mykey1 -path /user/xxxx/zone1&lt;/P&gt;&lt;P&gt;RemoteException: sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target&lt;/P&gt;</description>
    <pubDate>Fri, 16 Sep 2022 10:11:38 GMT</pubDate>
    <dc:creator>Vikas1</dc:creator>
    <dc:date>2022-09-16T10:11:38Z</dc:date>
    <item>
      <title>HDFS rest encryption zone unable to find valid certification path</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/HDFS-rest-encryption-zone-unable-to-find-valid-certification/m-p/39157#M23993</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cluster having the rest encryption enabled, I am able to create keys using "#hdfs key create mykey1" but not able to create encryption&amp;nbsp;zone on hdfs&amp;nbsp;directories.&lt;/P&gt;&lt;P&gt;Please find below steps for reference&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-bash-4.1$ hadoop key list&lt;BR /&gt;Listing keys for KeyProvider: KMSClientProvider[&lt;A href="https://fqdn:16000/kms/v1/" target="_blank"&gt;https://fqdn:16000/kms/v1/&lt;/A&gt;]&lt;BR /&gt;mykey2&lt;BR /&gt;mykey1&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I got below error when I am going to assign encryption zone to hdfs empty dir.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-sh-4.1$ hdfs crypto -createZone -keyName&amp;nbsp; mykey1 -path /user/xxxx/zone1&lt;/P&gt;&lt;P&gt;RemoteException: sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target&lt;/P&gt;</description>
      <pubDate>Fri, 16 Sep 2022 10:11:38 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/HDFS-rest-encryption-zone-unable-to-find-valid-certification/m-p/39157#M23993</guid>
      <dc:creator>Vikas1</dc:creator>
      <dc:date>2022-09-16T10:11:38Z</dc:date>
    </item>
    <item>
      <title>Re: HDFS rest encryption zone unable to find valid certification path</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/HDFS-rest-encryption-zone-unable-to-find-valid-certification/m-p/39316#M23994</link>
      <description>&lt;P&gt;Resolved: Enabled Kerberos Authentication for HTTP Web-Consoles (HDFS) and regenerated missing kerberos credentials&lt;/P&gt;&lt;P&gt;After changes done, I got below output.&lt;/P&gt;&lt;P&gt;-bash-4.1$ hdfs crypto -createZone -keyName mykey1 -path /user/xxxx/zone1&lt;/P&gt;&lt;P&gt;Added encryption zone /user/vgadade/zone1&lt;/P&gt;&lt;P&gt;-bash-4.1$&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2016 12:54:40 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/HDFS-rest-encryption-zone-unable-to-find-valid-certification/m-p/39316#M23994</guid>
      <dc:creator>Vikas1</dc:creator>
      <dc:date>2016-04-04T12:54:40Z</dc:date>
    </item>
    <item>
      <title>Re: HDFS rest encryption zone unable to find valid certification path</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/HDFS-rest-encryption-zone-unable-to-find-valid-certification/m-p/77204#M23995</link>
      <description>&lt;P&gt;Thanks for the solution. But do you know the true reason for enable&amp;nbsp;&lt;SPAN&gt;HTTP Web-Consoles (HDFS)?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jul 2018 07:48:32 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/HDFS-rest-encryption-zone-unable-to-find-valid-certification/m-p/77204#M23995</guid>
      <dc:creator>manuh</dc:creator>
      <dc:date>2018-07-20T07:48:32Z</dc:date>
    </item>
    <item>
      <title>Re: HDFS rest encryption zone unable to find valid certification path</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/HDFS-rest-encryption-zone-unable-to-find-valid-certification/m-p/77249#M23996</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/25247"&gt;@manuh&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I recommend you start a new thread since the answer to this one doesn't really make sense.&lt;/P&gt;&lt;P&gt;enabling kerberos for web consoles will not help resolve a PKIX error (which occurs when a client cannot find trust for the signer of the server certificate of the server to which the client is connecting).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Enabling kerberos for web-consoles will not solve TLS problems.&amp;nbsp; Something else that was done must have resolved the issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Enabling Kerberos Authentication for Web Consoles will require that any clients connecting to them use SPNEGO to authenticate.&amp;nbsp; This requires browser configuration and sometimes OS-level and krb5.conf configuration changes.&lt;/P&gt;&lt;P&gt;It is best to plan this move carefully and make sure you know how to configure clients to use SPNEGO if you are going to enable kerberos for web consoles.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you are having any problems similar to what was described in this thread, please give us some background of what you are trying to do and what isn't working.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ben&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jul 2018 23:08:16 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/HDFS-rest-encryption-zone-unable-to-find-valid-certification/m-p/77249#M23996</guid>
      <dc:creator>bgooley</dc:creator>
      <dc:date>2018-07-20T23:08:16Z</dc:date>
    </item>
  </channel>
</rss>

