<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: ssl error during oozie calling in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/ssl-error-during-oozie-calling/m-p/45144#M40452</link>
    <description>solved&lt;BR /&gt;&lt;A href="http://community.cloudera.com/t5/Batch-Processing-and-Workflow/oozie-cli-doesn-t-work-after-enabling-tls-option/m-p/45140" target="_blank"&gt;http://community.cloudera.com/t5/Batch-Processing-and-Workflow/oozie-cli-doesn-t-work-after-enabling-tls-option/m-p/45140&lt;/A&gt;</description>
    <pubDate>Thu, 15 Sep 2016 16:14:10 GMT</pubDate>
    <dc:creator>andrzej_jedrzej</dc:creator>
    <dc:date>2016-09-15T16:14:10Z</dc:date>
    <item>
      <title>ssl error during oozie calling</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/ssl-error-during-oozie-calling/m-p/45060#M40451</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a&amp;nbsp;problem with oozie on my cloudera cluster. I enabled TLS encryption for admin console and Agents. I specified Keystore and Truststore File location and passwords in configuration tab for oozie.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When i try to curl oozie:&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;oozie admin -oozie &lt;A href="https://ukgs2hdm02.cwglobal.local:11443/oozie" target="_blank"&gt;&lt;SPAN class="s2"&gt;https://ukgs2hdm02.cwglobal.local:11443/oozie&lt;/SPAN&gt;&lt;/A&gt; -status&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;Error: IO_ERROR : java.io.IOException: Error while connecting Oozie server. 
No of retries = 1. Exception = sun.security.validator.ValidatorException: PKIX path building failed:
sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target&lt;/PRE&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;I was thinking about importing host certificate to default java keystore but find this:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;/opt/jdk1.7.0_79/jre/lib/security/cacerts
/opt/cloudera/parcels/CDH-5.5.4-1.cdh5.5.4.p0.9/lib/hue/build/env/lib/python2.6/site-packages/boto-2.38.0-py2.6.egg/boto/cacerts
/usr/lib/jvm/java-1.5.0-gcj-1.5.0.0/jre/lib/security/cacerts
/usr/lib/jvm/java-1.7.0-openjdk-1.7.0.101.x86_64/jre/lib/security/cacerts
/usr/lib/jvm/java-1.6.0-openjdk-1.6.0.39.x86_64/jre/lib/security/cacerts
/usr/java/jdk1.7.0_67-cloudera/jre/lib/security/cacerts
/usr/java/jdk1.6.0_31/jre/lib/security/cacerts
/etc/pki/ca-trust/extracted/java/cacerts
/etc/pki/java/cacerts&lt;/PRE&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;and I don't know which one should I use?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Here are my files related to cert:&lt;/SPAN&gt;&lt;/P&gt;&lt;PRE&gt;-rw-r-----. 1 root         tls  1996 May 31 13:08 cdh_host.key
-rw-r-----. 1 root         tls  2159 May 31 13:08 cdh_host.keystore
-r--r-----. 1 oozie        tls  2159 Sep 13 09:45 cdh_host.oozie.keystore
-rw-r-----. 1 root         tls  1123 May 31 13:08 cdh_host.pem
-r-xr--r--. 1 cloudera-scm tls  8754 Sep  7 13:39 truststore.jks
-rw-r-----. 1 root         tls 11961 Sep  7 13:39 truststore.pem
-rw-r-----. 1 root         tls   789 May 31 13:08 ukgs2hdm02.cwglobal.local.cer&lt;/PRE&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;oozie&amp;nbsp;keystore&amp;nbsp;is the same as the host keystore.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Any ideas?&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Apr 2026 13:49:06 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/ssl-error-during-oozie-calling/m-p/45060#M40451</guid>
      <dc:creator>andrzej_jedrzej</dc:creator>
      <dc:date>2026-04-21T13:49:06Z</dc:date>
    </item>
    <item>
      <title>Re: ssl error during oozie calling</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/ssl-error-during-oozie-calling/m-p/45144#M40452</link>
      <description>solved&lt;BR /&gt;&lt;A href="http://community.cloudera.com/t5/Batch-Processing-and-Workflow/oozie-cli-doesn-t-work-after-enabling-tls-option/m-p/45140" target="_blank"&gt;http://community.cloudera.com/t5/Batch-Processing-and-Workflow/oozie-cli-doesn-t-work-after-enabling-tls-option/m-p/45140&lt;/A&gt;</description>
      <pubDate>Thu, 15 Sep 2016 16:14:10 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/ssl-error-during-oozie-calling/m-p/45144#M40452</guid>
      <dc:creator>andrzej_jedrzej</dc:creator>
      <dc:date>2016-09-15T16:14:10Z</dc:date>
    </item>
  </channel>
</rss>

