<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: how to rollback cloudera manager tls configuration without UI in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/how-to-rollback-cloudera-manager-tls-configuration-without/m-p/46485#M43971</link>
    <description>&lt;P&gt;I would recommend reviewing the Cloudera Manager log for clues, but, for now, access your Cloudera Manager database and run&amp;nbsp;the following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;delete from CONFIGS where ATTR='web_tls';&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This will disable TLS for the CM UI&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Afterward, try starting again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If that doesn't help, let us know.&lt;/P&gt;</description>
    <pubDate>Wed, 19 Oct 2016 23:43:06 GMT</pubDate>
    <dc:creator>bgooley</dc:creator>
    <dc:date>2016-10-19T23:43:06Z</dc:date>
    <item>
      <title>how to rollback cloudera manager tls configuration without UI</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/how-to-rollback-cloudera-manager-tls-configuration-without/m-p/46484#M43970</link>
      <description>&lt;P&gt;&lt;U&gt;Need help urgently.&lt;/U&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hi, Today I configured Cloudera Manager 5.4.1 to use HTTPS by following&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.cloudera.com/documentation/enterprise/5-4-x/topics/cm_sg_tls_browser.html#concept_hrs_f5d" target="_blank" rel="noopener"&gt;http://www.cloudera.com/documentation/enterprise/5-4-x/topics/cm_sg_tls_browser.html#concept_hrs_f5d&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I used self-signed certificate described in &lt;A href="http://www.cloudera.com/documentation/enterprise/5-4-x/topics/sg_self_signed_tls.html#xd_583c10bfdbd" target="_blank" rel="noopener"&gt;http://www.cloudera.com/documentation/enterprise/5-4-x/topics/sg_self_signed_tls.html#xd_583c10bfdbd&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;However, after restarting cloudera-scm-server, I could not open the cloudera manager in browser.&lt;/P&gt;
&lt;P&gt;“Openssl &amp;nbsp;s_client –connect “’ indicated the ssl connection was fine, but the browser always timed out. I’ve tried different browsers and cleaned the cache etc. Still the same. At this point, I would rather to roll it back.&lt;/P&gt;
&lt;P&gt;Is there a way to rollback the changes to use Http again?&amp;nbsp; Since I cannot access the cloudera manger UI, I can only do it thru command line. Does anyone know where the configuration is stored and how to change it?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please Help!&amp;nbsp; Thanks!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Nov 2019 14:10:12 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/how-to-rollback-cloudera-manager-tls-configuration-without/m-p/46484#M43970</guid>
      <dc:creator>kliu</dc:creator>
      <dc:date>2019-11-18T14:10:12Z</dc:date>
    </item>
    <item>
      <title>Re: how to rollback cloudera manager tls configuration without UI</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/how-to-rollback-cloudera-manager-tls-configuration-without/m-p/46485#M43971</link>
      <description>&lt;P&gt;I would recommend reviewing the Cloudera Manager log for clues, but, for now, access your Cloudera Manager database and run&amp;nbsp;the following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;delete from CONFIGS where ATTR='web_tls';&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This will disable TLS for the CM UI&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Afterward, try starting again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If that doesn't help, let us know.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Oct 2016 23:43:06 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/how-to-rollback-cloudera-manager-tls-configuration-without/m-p/46485#M43971</guid>
      <dc:creator>bgooley</dc:creator>
      <dc:date>2016-10-19T23:43:06Z</dc:date>
    </item>
    <item>
      <title>Re: how to rollback cloudera manager tls configuration without UI</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/how-to-rollback-cloudera-manager-tls-configuration-without/m-p/46486#M43972</link>
      <description>Thanks, that worked perfectly! Appreciated your quick help.</description>
      <pubDate>Thu, 20 Oct 2016 00:13:22 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/how-to-rollback-cloudera-manager-tls-configuration-without/m-p/46486#M43972</guid>
      <dc:creator>kliu</dc:creator>
      <dc:date>2016-10-20T00:13:22Z</dc:date>
    </item>
    <item>
      <title>Re: how to rollback cloudera manager tls configuration without UI</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/how-to-rollback-cloudera-manager-tls-configuration-without/m-p/48926#M43973</link>
      <description>&lt;P&gt;How to find the cloudera manager DB credentials? I do have the same issue. Not able to login to web UI after TLS configuration&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Dec 2016 23:33:32 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/how-to-rollback-cloudera-manager-tls-configuration-without/m-p/48926#M43973</guid>
      <dc:creator>SriniBI</dc:creator>
      <dc:date>2016-12-30T23:33:32Z</dc:date>
    </item>
    <item>
      <title>Re: how to rollback cloudera manager tls configuration without UI</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/how-to-rollback-cloudera-manager-tls-configuration-without/m-p/50194#M43974</link>
      <description>&lt;P&gt;I had a similar problem. I had enabled the &lt;STRONG&gt;agent_tls&lt;/STRONG&gt;, but the keystore field was not filled or the file was on a different location. &amp;nbsp;Now the server did not start anymore. I needed to rollback the setting, thx for your post.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I used mysql tool on the command-line to connect as root to MySQL db, and executed an update:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;use scm;
update CONFIGS set VALUE='false' where ATTR='agent_tls';
Query OK, 1 row affected (0.05 sec)&lt;/PRE&gt;&lt;P&gt;After a restart of cloudera-scm-server, the server was working again and I could enter the UI.&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jan 2017 14:18:24 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/how-to-rollback-cloudera-manager-tls-configuration-without/m-p/50194#M43974</guid>
      <dc:creator>MrBee</dc:creator>
      <dc:date>2017-01-31T14:18:24Z</dc:date>
    </item>
    <item>
      <title>Re: how to rollback cloudera manager tls configuration without UI</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/how-to-rollback-cloudera-manager-tls-configuration-without/m-p/53402#M43975</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Urgent&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/4054"&gt;@bgooley&lt;/a&gt;This not helped me. Its giving below&lt;BR /&gt;&lt;BR /&gt;scm=# delete from CONFIGS where ATTR='web_tls';&lt;BR /&gt;DELETE 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you give any other fix&lt;/P&gt;</description>
      <pubDate>Mon, 10 Apr 2017 11:47:46 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/how-to-rollback-cloudera-manager-tls-configuration-without/m-p/53402#M43975</guid>
      <dc:creator>kchaitanya</dc:creator>
      <dc:date>2017-04-10T11:47:46Z</dc:date>
    </item>
    <item>
      <title>Re: how to rollback cloudera manager tls configuration without UI</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/how-to-rollback-cloudera-manager-tls-configuration-without/m-p/53410#M43976</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/14957"&gt;@kchaitanya&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If that did not help, then it is likely there is another problem.&lt;/P&gt;&lt;P&gt;Please start a new thread and outline what you are trying to do and what is happening.&lt;/P&gt;&lt;P&gt;Also, make sure to review your /var/log/cloudera-scm-server/cloudera-scm-server.log for clues about what problem is occurring.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-Ben&lt;/P&gt;</description>
      <pubDate>Mon, 10 Apr 2017 15:04:24 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/how-to-rollback-cloudera-manager-tls-configuration-without/m-p/53410#M43976</guid>
      <dc:creator>bgooley</dc:creator>
      <dc:date>2017-04-10T15:04:24Z</dc:date>
    </item>
    <item>
      <title>Re: how to rollback cloudera manager tls configuration without UI</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/how-to-rollback-cloudera-manager-tls-configuration-without/m-p/53464#M43977</link>
      <description>Thank you for the reply &lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/4054"&gt;@bgooley&lt;/a&gt;, i fixed it by running below command&lt;BR /&gt;&lt;BR /&gt;delete from CONFIGS where ATTR='agent_tls';&lt;BR /&gt;&lt;BR /&gt;Thank you</description>
      <pubDate>Tue, 11 Apr 2017 02:42:08 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/how-to-rollback-cloudera-manager-tls-configuration-without/m-p/53464#M43977</guid>
      <dc:creator>kchaitanya</dc:creator>
      <dc:date>2017-04-11T02:42:08Z</dc:date>
    </item>
    <item>
      <title>Re: how to rollback cloudera manager tls configuration without UI</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/how-to-rollback-cloudera-manager-tls-configuration-without/m-p/53523#M43978</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/14957"&gt;@kchaitanya&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Indeed, if agent_tls is enabled even without web_tls and there is a problem with the certificate or trust store, then you would need to turn off agent_tls.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A big thanks for sharing that solution!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2017 20:40:20 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/how-to-rollback-cloudera-manager-tls-configuration-without/m-p/53523#M43978</guid>
      <dc:creator>bgooley</dc:creator>
      <dc:date>2017-04-11T20:40:20Z</dc:date>
    </item>
    <item>
      <title>Re: how to rollback cloudera manager tls configuration without UI</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/how-to-rollback-cloudera-manager-tls-configuration-without/m-p/283066#M43979</link>
      <description>&lt;P&gt;DB credential can be found here&amp;nbsp;/etc/cloudera-scm-server/db.properties.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Nov 2019 07:46:58 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/how-to-rollback-cloudera-manager-tls-configuration-without/m-p/283066#M43979</guid>
      <dc:creator>ram76</dc:creator>
      <dc:date>2019-11-15T07:46:58Z</dc:date>
    </item>
    <item>
      <title>Re: how to rollback cloudera manager tls configuration without UI</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/how-to-rollback-cloudera-manager-tls-configuration-without/m-p/299940#M43980</link>
      <description>&lt;P&gt;Urgent and this for CDP 7.1&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I ran below commands against scm database:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;delete from CONFIGS where ATTR='web_tls';&lt;BR /&gt;delete from CONFIGS where ATTR='agent_tls';&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But still seeing below in the Cloudera Manager logs:&lt;/P&gt;&lt;P&gt;2020-07-17 22:30:44,886 INFO MainThread:com.cloudera.server.cmf.Main: Successfully completed Auto Upgrade&lt;BR /&gt;2020-07-17 22:30:44,978 INFO MainThread:com.cloudera.server.cmf.Main: Agent RPC connections will use port: 7182&lt;BR /&gt;2020-07-17 22:30:44,978 INFO MainThread:com.cloudera.server.cmf.Main: Agent TLS certificates will be validated.&lt;BR /&gt;2020-07-17 22:30:44,985 INFO MainThread:com.cloudera.server.common.HttpConnectorServer: Max heartbeat processing thread: 6 and Max threads for CM agent avro http connector: 120&lt;BR /&gt;2020-07-17 22:30:45,029 INFO MainThread:com.cloudera.server.common.HttpConnectorServer: HttpConnectorServer port=7182&lt;BR /&gt;2020-07-17 22:30:45,029 INFO MainThread:com.cloudera.server.common.HttpConnectorServer: HttpConnectorServer IdleTime=300000&lt;BR /&gt;2020-07-17 22:30:45,058 INFO MainThread:org.eclipse.jetty.server.Server: jetty-9.4.14.v20181114; built: 2018-11-14T21:20:31.478Z; git: c4550056e785fb5665914545889f21dc136ad9e6; jvm 1.8.0_181-b13&lt;BR /&gt;2020-07-17 22:30:45,081 WARN MainThread:org.eclipse.jetty.security.SecurityHandler: ServletContext@o.e.j.s.ServletContextHandler@62408bf4{/,null,STARTING} has uncovered http methods for path: /*&lt;BR /&gt;2020-07-17 22:30:45,089 INFO MainThread:org.eclipse.jetty.server.handler.ContextHandler: Started o.e.j.s.ServletContextHandler@62408bf4{/,null,AVAILABLE}&lt;BR /&gt;2020-07-17 22:30:45,093 ERROR MainThread:com.cloudera.server.cmf.Main: Failed to start Agent listener.&lt;BR /&gt;2020-07-17 22:30:45,093 ERROR MainThread:com.cloudera.server.cmf.Main: Server failed.&lt;BR /&gt;org.apache.avro.AvroRuntimeException: java.io.IOException: Keystore was tampered with, or password was incorrect&lt;BR /&gt;at com.cloudera.server.common.HttpConnectorServer.start(HttpConnectorServer.java:224)&lt;BR /&gt;at com.cloudera.server.cmf.Main.startAgentServer(Main.java:590)&lt;BR /&gt;at com.cloudera.server.cmf.Main.run(Main.java:646)&lt;BR /&gt;at com.cloudera.server.cmf.Main.main(Main.java:247)&lt;BR /&gt;Caused by: java.io.IOException: Keystore was tampered with, or password was incorrect&lt;BR /&gt;at sun.security.provider.JavaKeyStore.engineLoad(JavaKeyStore.java:780)&lt;BR /&gt;at sun.security.provider.JavaKeyStore$JKS.engineLoad(JavaKeyStore.java:56)&lt;BR /&gt;at sun.security.provider.KeyStoreDelegator.engineLoad(KeyStoreDelegator.java:224)&lt;BR /&gt;at sun.security.provider.JavaKeyStore$DualFormatJKS.engineLoad(JavaKeyStore.java:70)&lt;BR /&gt;at java.security.KeyStore.load(KeyStore.java:1445)&lt;BR /&gt;at org.eclipse.jetty.util.security.CertificateUtils.getKeyStore(CertificateUtils.java:54)&lt;BR /&gt;at org.eclipse.jetty.util.ssl.SslContextFactory.loadKeyStore(SslContextFactory.java:1137)&lt;BR /&gt;at org.eclipse.jetty.util.ssl.SslContextFactory.load(SslContextFactory.java:313)&lt;BR /&gt;at org.eclipse.jetty.util.ssl.SslContextFactory.doStart(SslContextFactory.java:248)&lt;BR /&gt;at org.eclipse.jetty.util.component.AbstractLifeCycle.start(AbstractLifeCycle.java:68)&lt;BR /&gt;at org.eclipse.jetty.util.component.ContainerLifeCycle.start(ContainerLifeCycle.java:138)&lt;BR /&gt;at org.eclipse.jetty.util.component.ContainerLifeCycle.doStart(ContainerLifeCycle.java:117)&lt;BR /&gt;at org.eclipse.jetty.server.SslConnectionFactory.doStart(SslConnectionFactory.java:94)&lt;BR /&gt;at org.eclipse.jetty.util.component.AbstractLifeCycle.start(AbstractLifeCycle.java:68)&lt;BR /&gt;at org.eclipse.jetty.util.component.ContainerLifeCycle.start(ContainerLifeCycle.java:138)&lt;BR /&gt;at org.eclipse.jetty.util.component.ContainerLifeCycle.doStart(ContainerLifeCycle.java:117)&lt;BR /&gt;at org.eclipse.jetty.server.AbstractConnector.doStart(AbstractConnector.java:282)&lt;BR /&gt;at org.eclipse.jetty.server.AbstractNetworkConnector.doStart(AbstractNetworkConnector.java:81)&lt;BR /&gt;at org.eclipse.jetty.server.ServerConnector.doStart(ServerConnector.java:236)&lt;BR /&gt;at org.eclipse.jetty.util.component.AbstractLifeCycle.start(AbstractLifeCycle.java:68)&lt;BR /&gt;at org.eclipse.jetty.server.Server.doStart(Server.java:394)&lt;BR /&gt;at org.eclipse.jetty.util.component.AbstractLifeCycle.start(AbstractLifeCycle.java:68)&lt;BR /&gt;at com.cloudera.server.common.HttpConnectorServer.start(HttpConnectorServer.java:222)&lt;BR /&gt;... 3 more&lt;BR /&gt;Caused by: java.security.UnrecoverableKeyException: Password verification failed&lt;BR /&gt;at sun.security.provider.JavaKeyStore.engineLoad(JavaKeyStore.java:778)&lt;BR /&gt;... 25 more&lt;BR /&gt;2020-07-17 22:30:54,291 INFO ScmActive-0:com.cloudera.server.cmf.components.ScmActive: ScmActive completed successfully.&lt;BR /&gt;2020-07-17 22:31:09,276 INFO pool-201-thread-1:com.cloudera.server.cmf.components.CmServerStateSynchronizer: Cleanup is started.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Still not able to access the Cloudera Manager UI, please assist.&lt;/P&gt;</description>
      <pubDate>Sat, 18 Jul 2020 02:39:16 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/how-to-rollback-cloudera-manager-tls-configuration-without/m-p/299940#M43980</guid>
      <dc:creator>mksl</dc:creator>
      <dc:date>2020-07-18T02:39:16Z</dc:date>
    </item>
    <item>
      <title>Re: how to rollback cloudera manager tls configuration without UI</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/how-to-rollback-cloudera-manager-tls-configuration-without/m-p/306476#M43981</link>
      <description>&lt;P&gt;Today I ran into this same issue but the solutions in the post didn't resolve the problem.&amp;nbsp; I found each time you would start&amp;nbsp;cloudera-scm-server (sudo systemctl start cloudera-scm-server) it would just add the entries back to the database we are instructed to delete.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The following did resolve the problem -&lt;/P&gt;&lt;P&gt;Edit&amp;nbsp;/var/lib/cloudera-scm-server/certmanager/cm_init.txt&lt;/P&gt;&lt;P&gt;Change the following top 3 lines from true to false as follows.&lt;/P&gt;&lt;P&gt;setsettings AGENT_TLS false&lt;/P&gt;&lt;P&gt;setsettings WEB_TLS false&lt;/P&gt;&lt;P&gt;setsettings NEED_AGENT_VALIDATION false&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then stop and start the&amp;nbsp;cloudera-scm-server.&lt;/P&gt;&lt;P&gt;This time you will see the entries back in the DB but they'll be set to false.&lt;/P&gt;&lt;P&gt;On the database server you can run the following to confirm they are set to false now.&lt;/P&gt;&lt;P&gt;select * from CONFIGS where ATTR='web_tls';&lt;/P&gt;&lt;P&gt;select * from CONFIGS where ATTR='agent_tls';&lt;/P&gt;</description>
      <pubDate>Thu, 26 Nov 2020 00:22:29 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/how-to-rollback-cloudera-manager-tls-configuration-without/m-p/306476#M43981</guid>
      <dc:creator>K_P</dc:creator>
      <dc:date>2020-11-26T00:22:29Z</dc:date>
    </item>
  </channel>
</rss>

