<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Hue don't sends intermediate certificates during https session in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Hue-don-t-sends-intermediate-certificates-during-https/m-p/64933#M37697</link>
    <description>&lt;P&gt;I found this very helpful post during my task to enable TLS with our corporate CA and had the same problem.&lt;/P&gt;&lt;P&gt;To make it a little more complicated, we have the Hue Load Balancer enabled additional to the normal Hue server.&lt;/P&gt;&lt;P&gt;With the load balancer, an apache webserver is put in front of the cherrypi webserver.&lt;/P&gt;&lt;P&gt;So the configuration for the intermediate certificate has to be put in the httpd.conf of the loadbalancers apache.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This can be done with Cloudera Manager with the&lt;/P&gt;&lt;DIV class="param-spec-property"&gt;&lt;DIV class="header-column"&gt;&lt;DIV class="display-name"&gt;&lt;STRONG&gt;Load Balancer Advanced Configuration Snippet (Safety Valve) for httpd.conf&lt;/STRONG&gt; entry of the Hue load balancer configuration.&lt;/DIV&gt;&lt;DIV class="display-name"&gt;Just add the following line:&lt;/DIV&gt;&lt;DIV class="display-name"&gt;&lt;PRE&gt;SSLCertificateChainFile /path/to/intermediate.crt&lt;/PRE&gt;It will be added right next to the SSL certificate configuration that could be done via the normal configuraiton fields of the load balancer.&lt;/DIV&gt;&lt;DIV class="display-name"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="display-name"&gt;As with in Isegrims post, the certificate must follow the rules for a PEM file, in fact, the same file can be used by both webservers.&lt;/DIV&gt;&lt;DIV class="display-name"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
    <pubDate>Mon, 26 Feb 2018 17:03:52 GMT</pubDate>
    <dc:creator>Stefanhu</dc:creator>
    <dc:date>2018-02-26T17:03:52Z</dc:date>
    <item>
      <title>Hue don't sends intermediate certificates during https session</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Hue-don-t-sends-intermediate-certificates-during-https/m-p/43869#M37694</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've tried to implement https for Hue web interface, but it works only in one half.&lt;/P&gt;&lt;P&gt;Hue don't sends my Sub CA cert included in 'ssl_cacerts' setting.&lt;BR /&gt;&lt;BR /&gt;My certs chierarchy is as follows:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;hue.my.domain.com&lt;/STRONG&gt; - &lt;U&gt;&lt;EM&gt;Signed by MySubCA&lt;/EM&gt;&lt;/U&gt; - this is sent properly by Hue&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;MySubCA&lt;/STRONG&gt; - &lt;U&gt;&lt;EM&gt;Signed by MyCorporateCA&lt;/EM&gt;&lt;/U&gt; - this is not being send by Hue&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;MyCorporateCA&lt;/STRONG&gt; - &lt;U&gt;&lt;EM&gt;Trusted cert&lt;/EM&gt;&lt;/U&gt;, included in every corporate station. - this does not need to be sent by Hue&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;MySubCA I was including in hue.my.domain.cert (once at the beginning of PEM file, once at the end) - it did not work - only hue.my.domain.com cert was sent or error was raised.&lt;/P&gt;&lt;P&gt;Then I've left only my.domain.com cert in this PEM file and inserted MySubCA cert into another PEM file and placed it's path in CM HueServer Configuration (Security) in ssl_cacerts parameter. But this also didn't help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How to make ssl_cacerts Hue configuration parameter to be respected by Hue?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Apr 2026 13:49:54 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Hue-don-t-sends-intermediate-certificates-during-https/m-p/43869#M37694</guid>
      <dc:creator>Isegrim</dc:creator>
      <dc:date>2026-04-21T13:49:54Z</dc:date>
    </item>
    <item>
      <title>Re: Hue don't sends intermediate certificates during https session</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Hue-don-t-sends-intermediate-certificates-during-https/m-p/44620#M37695</link>
      <description>&lt;P&gt;Does anyone know where is error log for runcherryPy server for Hue in CDH 5.7 ?&lt;BR /&gt;in CDH 5.6 and earlier it was in runchserver.out and from CDH 5.7 it is gone &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;BR /&gt;I see some errors there regarding this ssl issue, but in earlier CDH then I have now.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Sep 2016 10:04:29 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Hue-don-t-sends-intermediate-certificates-during-https/m-p/44620#M37695</guid>
      <dc:creator>Isegrim</dc:creator>
      <dc:date>2016-09-01T10:04:29Z</dc:date>
    </item>
    <item>
      <title>Re: Hue don't sends intermediate certificates during https session</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Hue-don-t-sends-intermediate-certificates-during-https/m-p/44634#M37696</link>
      <description>&lt;P&gt;Together with my collegue we've manage to solve the problem.&lt;/P&gt;&lt;P&gt;After diging Hue sources he has discovered undocumented option for ssl cert chains:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ssl_certificate_chain&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have edited "Hue Service Advanced Configuration Snippet (Safety Valve) for hue_safety_valve.ini" of Hue configuration in CM and added:&lt;/P&gt;&lt;PRE&gt;[desktop]
ssl_certificate_chain=/path/to/certs/myDomainCert.IntermediateCert.pem&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The certificate chain MUST have at the top of pem file &lt;STRONG&gt;hue.my.domain.com&lt;/STRONG&gt; cert and after this &lt;STRONG&gt;MySubCA&lt;/STRONG&gt;, despite proper set of&lt;/P&gt;&lt;P&gt;ssl_certificate=/path/to/certs/myDomainCert.pem&lt;/P&gt;&lt;P&gt;ssl_private_key=/path/to/certs/myDomainCert.key&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.digicert.com/ssl-support/pem-ssl-creation.htm" target="_blank"&gt;https://www.digicert.com/ssl-support/pem-ssl-creation.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did not put there &lt;STRONG&gt;MyCorporateCA&lt;/STRONG&gt;&amp;nbsp; because it is already in every corporate computer and browser properly read it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Sep 2016 15:40:05 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Hue-don-t-sends-intermediate-certificates-during-https/m-p/44634#M37696</guid>
      <dc:creator>Isegrim</dc:creator>
      <dc:date>2016-09-01T15:40:05Z</dc:date>
    </item>
    <item>
      <title>Re: Hue don't sends intermediate certificates during https session</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Hue-don-t-sends-intermediate-certificates-during-https/m-p/64933#M37697</link>
      <description>&lt;P&gt;I found this very helpful post during my task to enable TLS with our corporate CA and had the same problem.&lt;/P&gt;&lt;P&gt;To make it a little more complicated, we have the Hue Load Balancer enabled additional to the normal Hue server.&lt;/P&gt;&lt;P&gt;With the load balancer, an apache webserver is put in front of the cherrypi webserver.&lt;/P&gt;&lt;P&gt;So the configuration for the intermediate certificate has to be put in the httpd.conf of the loadbalancers apache.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This can be done with Cloudera Manager with the&lt;/P&gt;&lt;DIV class="param-spec-property"&gt;&lt;DIV class="header-column"&gt;&lt;DIV class="display-name"&gt;&lt;STRONG&gt;Load Balancer Advanced Configuration Snippet (Safety Valve) for httpd.conf&lt;/STRONG&gt; entry of the Hue load balancer configuration.&lt;/DIV&gt;&lt;DIV class="display-name"&gt;Just add the following line:&lt;/DIV&gt;&lt;DIV class="display-name"&gt;&lt;PRE&gt;SSLCertificateChainFile /path/to/intermediate.crt&lt;/PRE&gt;It will be added right next to the SSL certificate configuration that could be done via the normal configuraiton fields of the load balancer.&lt;/DIV&gt;&lt;DIV class="display-name"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="display-name"&gt;As with in Isegrims post, the certificate must follow the rules for a PEM file, in fact, the same file can be used by both webservers.&lt;/DIV&gt;&lt;DIV class="display-name"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 26 Feb 2018 17:03:52 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Hue-don-t-sends-intermediate-certificates-during-https/m-p/64933#M37697</guid>
      <dc:creator>Stefanhu</dc:creator>
      <dc:date>2018-02-26T17:03:52Z</dc:date>
    </item>
  </channel>
</rss>

