<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question cloudbreak openstack SSL error , after put .crt file in certs/trusted in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/cloudbreak-openstack-SSL-error-after-put-crt-file-in-certs/m-p/156069#M36335</link>
    <description>&lt;P&gt;Dear team&lt;/P&gt;&lt;P&gt;(I posted the same content in github &lt;A href="https://github.com/sequenceiq/cloudbreak/issues/1825" target="_blank"&gt;https://github.com/sequenceiq/cloudbreak/issues/1825&lt;/A&gt; )&lt;/P&gt;&lt;P&gt;I am trying to use cloudbreak to create Hadoop cluster with our Openstack environment.&lt;/P&gt;&lt;P&gt;but got some errors when create credentials.&lt;/P&gt;&lt;P&gt;Enviroment:&lt;/P&gt;&lt;P&gt;1. Openstack version:  Juno&lt;/P&gt;&lt;P&gt;2. CentOS Linux release 7.2&lt;/P&gt;&lt;P&gt;I found the same problem in &lt;A href="https://github.com/sequenceiq/cloudbreak/issues/948"&gt;#948&lt;/A&gt; , and tried the same approach,&lt;/P&gt;&lt;P&gt;1. copy .crt file into docker&lt;/P&gt;&lt;P&gt;2. use "keytool -import" to import it into /etc/ssl/certs/java/cacerts&lt;/P&gt;&lt;P&gt;3. restart container cbreak_cloudbreak_1&lt;/P&gt;&lt;P&gt;4. run "credential create" and got failed.&lt;/P&gt;&lt;P&gt;CLI:&lt;/P&gt;&lt;PRE&gt;&amp;lt;code&amp;gt;credential create --OPENSTACK --name ynwm --description "keystone.(masked)" --userName sso --password (masked) --tenantName query-engine-test --endPoint &lt;A href="https://keystone.(masked):5000/v2.0/" target="_blank"&gt;https://keystone.(masked):5000/v2.0/&lt;/A&gt; --sshKeyString "ssh-rsa AAA.....(masked)..5Q== sso_created" --publicInAccount true 
&lt;/PRE&gt;
&lt;P&gt;error:&lt;/P&gt;&lt;PRE&gt;&amp;lt;code&amp;gt;Command failed java.lang.RuntimeException: Failed to verify the credential: Could not verify credential [credential: 'ynwm'], detailed message: javax.net.ssl.SSLHandshakeException: sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
&lt;/PRE&gt;
&lt;P style="margin-left: 20px;"&gt;I found another document &lt;/P&gt;&lt;P&gt;&lt;A href="https://github.com/sequenceiq/cloudbreak-docs/blob/master/docs/openstack/deployer.md"&gt;https://github.com/sequenceiq/cloudbreak-docs/blob/master/docs/openstack/deployer.md&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://github.com/sequenceiq/cloudbreak-docs/blob/master/docs/configuration.md"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;In which it says, &lt;/P&gt;&lt;BLOCKQUOTE&gt;
&lt;P&gt;If your OpenStack is secured with a self-signed certificate, you need to import that certificate into Cloudbreak, or else Cloudbreak won't be able to communicate with your OpenStack. To import the certificate, place the certificate file in the generated certs directory /certs/trusted/. The trusted directory does not exist by default, so you need to create it. Cloudbreak will automatically pick up these certificates and import them into its truststore upon start.&lt;/P&gt;&lt;P&gt;so I copied my .crt file into certs/trusted,&lt;/P&gt;&lt;P&gt;and restarted cbd, &lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;PRE&gt;&amp;lt;code&amp;gt;[sso@cloudbreak02 ~/tools/cloudbreak-deployment]$ sudo docker exec -it cbreak_cloudbreak_1 bash
root@dd24262dd30c:/# ls -al /certs/trusted/
total 16
drwxr-xr-x 2 root root 4096 Jul 29 01:41 .
drwxr-xr-x 3 root root 4096 Jul 29 01:39 ..
-rw-r--r-- 1 root root 4753 Jul 27 08:17 sso.crt
root@dd24262dd30c:/#
&lt;/PRE&gt;

&lt;PRE&gt;&amp;lt;code&amp;gt;sudo cbd start
sudo cbd util cloudbreak-shell
credential create --OPENSTACK ....(the same with the command above)
&lt;/PRE&gt;
&lt;P&gt;however still got the SSL error:&lt;/P&gt;&lt;PRE&gt;&amp;lt;code&amp;gt;/cbreak_cloudbreak_1 | Caused by: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
/cbreak_cloudbreak_1 |  at sun.security.provider.certpath.SunCertPathBuilder.build(SunCertPathBuilder.java:141)
/cbreak_cloudbreak_1 |  at sun.security.provider.certpath.SunCertPathBuilder.engineBuild(SunCertPathBuilder.java:126)
/cbreak_cloudbreak_1 |  at java.security.cert.CertPathBuilder.build(CertPathBuilder.java:280)
/cbreak_cloudbreak_1 |  at sun.security.validator.PKIXValidator.doBuild(PKIXValidator.java:382)
/cbreak_cloudbreak_1 |  ... 82 common frames omitted
&lt;/PRE&gt;
&lt;P&gt;Thanks for any possible help&lt;/P&gt;</description>
    <pubDate>Fri, 29 Jul 2016 09:06:14 GMT</pubDate>
    <dc:creator>sso</dc:creator>
    <dc:date>2016-07-29T09:06:14Z</dc:date>
    <item>
      <title>cloudbreak openstack SSL error , after put .crt file in certs/trusted</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/cloudbreak-openstack-SSL-error-after-put-crt-file-in-certs/m-p/156069#M36335</link>
      <description>&lt;P&gt;Dear team&lt;/P&gt;&lt;P&gt;(I posted the same content in github &lt;A href="https://github.com/sequenceiq/cloudbreak/issues/1825" target="_blank"&gt;https://github.com/sequenceiq/cloudbreak/issues/1825&lt;/A&gt; )&lt;/P&gt;&lt;P&gt;I am trying to use cloudbreak to create Hadoop cluster with our Openstack environment.&lt;/P&gt;&lt;P&gt;but got some errors when create credentials.&lt;/P&gt;&lt;P&gt;Enviroment:&lt;/P&gt;&lt;P&gt;1. Openstack version:  Juno&lt;/P&gt;&lt;P&gt;2. CentOS Linux release 7.2&lt;/P&gt;&lt;P&gt;I found the same problem in &lt;A href="https://github.com/sequenceiq/cloudbreak/issues/948"&gt;#948&lt;/A&gt; , and tried the same approach,&lt;/P&gt;&lt;P&gt;1. copy .crt file into docker&lt;/P&gt;&lt;P&gt;2. use "keytool -import" to import it into /etc/ssl/certs/java/cacerts&lt;/P&gt;&lt;P&gt;3. restart container cbreak_cloudbreak_1&lt;/P&gt;&lt;P&gt;4. run "credential create" and got failed.&lt;/P&gt;&lt;P&gt;CLI:&lt;/P&gt;&lt;PRE&gt;&amp;lt;code&amp;gt;credential create --OPENSTACK --name ynwm --description "keystone.(masked)" --userName sso --password (masked) --tenantName query-engine-test --endPoint &lt;A href="https://keystone.(masked):5000/v2.0/" target="_blank"&gt;https://keystone.(masked):5000/v2.0/&lt;/A&gt; --sshKeyString "ssh-rsa AAA.....(masked)..5Q== sso_created" --publicInAccount true 
&lt;/PRE&gt;
&lt;P&gt;error:&lt;/P&gt;&lt;PRE&gt;&amp;lt;code&amp;gt;Command failed java.lang.RuntimeException: Failed to verify the credential: Could not verify credential [credential: 'ynwm'], detailed message: javax.net.ssl.SSLHandshakeException: sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
&lt;/PRE&gt;
&lt;P style="margin-left: 20px;"&gt;I found another document &lt;/P&gt;&lt;P&gt;&lt;A href="https://github.com/sequenceiq/cloudbreak-docs/blob/master/docs/openstack/deployer.md"&gt;https://github.com/sequenceiq/cloudbreak-docs/blob/master/docs/openstack/deployer.md&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://github.com/sequenceiq/cloudbreak-docs/blob/master/docs/configuration.md"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;In which it says, &lt;/P&gt;&lt;BLOCKQUOTE&gt;
&lt;P&gt;If your OpenStack is secured with a self-signed certificate, you need to import that certificate into Cloudbreak, or else Cloudbreak won't be able to communicate with your OpenStack. To import the certificate, place the certificate file in the generated certs directory /certs/trusted/. The trusted directory does not exist by default, so you need to create it. Cloudbreak will automatically pick up these certificates and import them into its truststore upon start.&lt;/P&gt;&lt;P&gt;so I copied my .crt file into certs/trusted,&lt;/P&gt;&lt;P&gt;and restarted cbd, &lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;PRE&gt;&amp;lt;code&amp;gt;[sso@cloudbreak02 ~/tools/cloudbreak-deployment]$ sudo docker exec -it cbreak_cloudbreak_1 bash
root@dd24262dd30c:/# ls -al /certs/trusted/
total 16
drwxr-xr-x 2 root root 4096 Jul 29 01:41 .
drwxr-xr-x 3 root root 4096 Jul 29 01:39 ..
-rw-r--r-- 1 root root 4753 Jul 27 08:17 sso.crt
root@dd24262dd30c:/#
&lt;/PRE&gt;

&lt;PRE&gt;&amp;lt;code&amp;gt;sudo cbd start
sudo cbd util cloudbreak-shell
credential create --OPENSTACK ....(the same with the command above)
&lt;/PRE&gt;
&lt;P&gt;however still got the SSL error:&lt;/P&gt;&lt;PRE&gt;&amp;lt;code&amp;gt;/cbreak_cloudbreak_1 | Caused by: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
/cbreak_cloudbreak_1 |  at sun.security.provider.certpath.SunCertPathBuilder.build(SunCertPathBuilder.java:141)
/cbreak_cloudbreak_1 |  at sun.security.provider.certpath.SunCertPathBuilder.engineBuild(SunCertPathBuilder.java:126)
/cbreak_cloudbreak_1 |  at java.security.cert.CertPathBuilder.build(CertPathBuilder.java:280)
/cbreak_cloudbreak_1 |  at sun.security.validator.PKIXValidator.doBuild(PKIXValidator.java:382)
/cbreak_cloudbreak_1 |  ... 82 common frames omitted
&lt;/PRE&gt;
&lt;P&gt;Thanks for any possible help&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jul 2016 09:06:14 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/cloudbreak-openstack-SSL-error-after-put-crt-file-in-certs/m-p/156069#M36335</guid>
      <dc:creator>sso</dc:creator>
      <dc:date>2016-07-29T09:06:14Z</dc:date>
    </item>
    <item>
      <title>Re: cloudbreak openstack SSL error , after put .crt file in certs/trusted</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/cloudbreak-openstack-SSL-error-after-put-crt-file-in-certs/m-p/156070#M36336</link>
      <description>&lt;PRE&gt;/cbreak_cloudbreak_1 | Importing certificates to the default Java certificate  trust store.
/cbreak_registrator_1 | 2016/07/29 01:44:42 registrator: added: dd24262dd30c af7ab373046f:cbreak_cloudbreak_1:8080
/cbreak_consul_1 |     2016/07/29 01:44:42 [INFO] agent: Synced service 'af7ab373046f:cbreak_cloudbreak_1:8080'
/cbreak_cloudbreak_1 | Certificate was added to keystore
/cbreak_cloudbreak_1 | Certificate added to default Java trust store with alias sso.crt.
/cbreak_cloudbreak_1 | Starting the Cloudbreak application...
/cbreak_cloudbreak_1 | + '[' true == false ']'
/cbreak_cloudbreak_1 | + java -jar /cloudbreak.jar&lt;/PRE&gt;&lt;P&gt;I checked log file and found "Certificate added to default Java trust store with alias sso.crt", &lt;/P&gt;&lt;P&gt;so I think the .crt file is added correctly.&lt;/P&gt;&lt;P&gt;However I still get SSL error when access the HTTPS endpoint.&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jul 2016 10:04:56 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/cloudbreak-openstack-SSL-error-after-put-crt-file-in-certs/m-p/156070#M36336</guid>
      <dc:creator>sso</dc:creator>
      <dc:date>2016-07-29T10:04:56Z</dc:date>
    </item>
    <item>
      <title>Re: cloudbreak openstack SSL error , after put .crt file in certs/trusted</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/cloudbreak-openstack-SSL-error-after-put-crt-file-in-certs/m-p/156071#M36337</link>
      <description>&lt;P&gt;Self response:&lt;/P&gt;&lt;P&gt;This problem is resolved.&lt;/P&gt;&lt;P&gt;Because I imported a wrong .crt file, which is not for our HTTPS server, the "credential create" command failed.&lt;/P&gt;&lt;P&gt;After putting the correct .crt file under "certs/trusted", I created a new &lt;/P&gt;&lt;P&gt;credential successfully.&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jul 2016 14:09:22 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/cloudbreak-openstack-SSL-error-after-put-crt-file-in-certs/m-p/156071#M36337</guid>
      <dc:creator>sso</dc:creator>
      <dc:date>2016-07-29T14:09:22Z</dc:date>
    </item>
    <item>
      <title>Re: cloudbreak openstack SSL error , after put .crt file in certs/trusted</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/cloudbreak-openstack-SSL-error-after-put-crt-file-in-certs/m-p/156072#M36338</link>
      <description>&lt;P&gt;Glad that it worked out, let us know if you believe something is missing from the docs and can be improved.&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jul 2016 16:13:19 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/cloudbreak-openstack-SSL-error-after-put-crt-file-in-certs/m-p/156072#M36338</guid>
      <dc:creator>Krisz</dc:creator>
      <dc:date>2016-07-29T16:13:19Z</dc:date>
    </item>
  </channel>
</rss>

