<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Issue with NameNode startup after enabling SSL in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Issue-with-NameNode-startup-after-enabling-SSL/m-p/170500#M54069</link>
    <description>&lt;P&gt;@&lt;A href="https://community.hortonworks.com/users/15990/m3l8.html"&gt;Michael Locatelli&lt;/A&gt;&lt;A href="https://community.hortonworks.com/users/15990/m3l8.html"&gt; &lt;/A&gt;&lt;/P&gt;&lt;P&gt;thats good to hear , feel free to add me for any SSL issues.&lt;/P&gt;</description>
    <pubDate>Sat, 11 Feb 2017 06:26:13 GMT</pubDate>
    <dc:creator>apappu</dc:creator>
    <dc:date>2017-02-11T06:26:13Z</dc:date>
    <item>
      <title>Issue with NameNode startup after enabling SSL</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Issue-with-NameNode-startup-after-enabling-SSL/m-p/170495#M54064</link>
      <description>&lt;P&gt;I'm setting up a 4 node HDP 2.5 cluster with a requirement to encrypt all data in transit. I've been following the documentation from here: &lt;A href="https://docs.hortonworks.com/HDPDocuments/HDP2/HDP-2.5.0/bk_security/content/ch_hdp-security-guide-wire-encryption.html" target="_blank"&gt;https://docs.hortonworks.com/HDPDocuments/HDP2/HDP-2.5.0/bk_security/content/ch_hdp-security-guide-wire-encryption.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I am using a certificate signed by my company's Issuing CA. The following is in my server.keystore.jks (sensitive bits masked)&lt;/P&gt;&lt;PRE&gt;&amp;lt;server's FQDN&amp;gt;, Feb 10, 2017, PrivateKeyEntry, 
Certificate fingerprint (SHA1): B6:DA:29:57:27:10:D3:97:8D:CD:49:6C:87:82:9F:64:DD:XX:XX:XX 
&amp;lt;company&amp;gt; issuing ca, Feb 10, 2017, trustedCertEntry, 
Certificate fingerprint (SHA1): F7:20:77:9E:08:4F:20:2E:E6:8C:78:5D:EA:39:91:6F:D7:XX:XX:XX 
&amp;lt;company&amp;gt; root ca, Feb 10, 2017, trustedCertEntry, 
Certificate fingerprint (SHA1): 8D:4A:EA:A6:43:71:83:FE:44:FA:E5:04:D7:E3:5B:3A:45:XX:XX:XX&lt;/PRE&gt;&lt;P&gt;After configuring the system to use the keys and restarting the HDFS service in Ambari, I can get the DataNode to start up. When the NameNode starts up, the service comes up but then it does a check using curl. The following error shows up in the error log:&lt;/P&gt;&lt;PRE&gt;resource_management.core.exceptions.Fail: Execution of 'curl -sS -L -w '%{http_code}' -X GET -k 'https://&amp;lt;server's FQDN&amp;gt;:50470/webhdfs/v1/tmp?op=GETFILESTATUS&amp;amp;user.name=hdfs' 1&amp;gt;/tmp/tmpiWgx4l 2&amp;gt;/tmp/tmpHLEISr' returned 35.
curl: (35) NSS: client certificate not found (nickname not specified)
000&lt;/PRE&gt;&lt;P&gt;I get the same result if I try to run the same command on the command line. In addition, if I try to access the same URL from Chrome, I'm getting ERR_BAD_SSL_CLIENT_AUTH_CERT back. I don't have a lot of experience setting up SSL/TLS and am pretty much stuck at this point. Any help would be greatly appreciated.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;</description>
      <pubDate>Fri, 16 Sep 2022 11:03:42 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Issue-with-NameNode-startup-after-enabling-SSL/m-p/170495#M54064</guid>
      <dc:creator>m3l8</dc:creator>
      <dc:date>2022-09-16T11:03:42Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with NameNode startup after enabling SSL</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Issue-with-NameNode-startup-after-enabling-SSL/m-p/170496#M54065</link>
      <description>&lt;P&gt;@&lt;A href="https://community.hortonworks.com/users/15990/m3l8.html"&gt;Michael Locatelli&lt;/A&gt;&lt;/P&gt;&lt;P&gt;You will have to disable the client auth at HDFS side.&lt;/P&gt;&lt;P&gt;set hadoop.ssl.require.client.cert=false  and restart the services.&lt;/P&gt;&lt;P&gt;You can follow the article that I have published some time back at &lt;A href="https://community.hortonworks.com/articles/52875/enable-https-for-hdfs.html" target="_blank"&gt;https://community.hortonworks.com/articles/52875/enable-https-for-hdfs.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 11 Feb 2017 05:52:20 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Issue-with-NameNode-startup-after-enabling-SSL/m-p/170496#M54065</guid>
      <dc:creator>apappu</dc:creator>
      <dc:date>2017-02-11T05:52:20Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with NameNode startup after enabling SSL</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Issue-with-NameNode-startup-after-enabling-SSL/m-p/170497#M54066</link>
      <description>&lt;P&gt;hadoop.ssl.require.client.cert is already set to false in core-site.xml is already set to false&lt;/P&gt;</description>
      <pubDate>Sat, 11 Feb 2017 05:54:53 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Issue-with-NameNode-startup-after-enabling-SSL/m-p/170497#M54066</guid>
      <dc:creator>m3l8</dc:creator>
      <dc:date>2017-02-11T05:54:53Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with NameNode startup after enabling SSL</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Issue-with-NameNode-startup-after-enabling-SSL/m-p/170498#M54067</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/15990/m3l8.html" nodeid="15990"&gt;@Michael Locatelli&lt;/A&gt; &lt;/P&gt;&lt;P&gt;In keystore files have only corresponding cert - remove truststore certs and other stuff, since we are not defining any alias name in the configurations.&lt;/P&gt;&lt;P&gt;Ex: Correct keystore file should look alike if i list it like,&lt;/P&gt;&lt;P&gt;keytool -list -keystore skeystore.jks&lt;/P&gt;&lt;P&gt;-------------&lt;/P&gt;&lt;P&gt;Keystore type: JKS
Keystore provider: SUN
Your keystore contains 1 entry
apappu.hdp.com, Nov 16, 2016, PrivateKeyEntry,
Certificate fingerprint (SHA1): 50:2B:EF:1F:58:07:C3:0A:C6:29:B8:49:7B:98:1B:DD:A0:A8:33:A9&lt;/P&gt;&lt;P&gt;-------------&lt;/P&gt;&lt;P&gt;If you observe in the outout - there is no trustedCertEntry.&lt;/P&gt;</description>
      <pubDate>Sat, 11 Feb 2017 05:58:05 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Issue-with-NameNode-startup-after-enabling-SSL/m-p/170498#M54067</guid>
      <dc:creator>apappu</dc:creator>
      <dc:date>2017-02-11T05:58:05Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with NameNode startup after enabling SSL</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Issue-with-NameNode-startup-after-enabling-SSL/m-p/170499#M54068</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/11311/apappu.html" nodeid="11311"&gt;@apappu&lt;/A&gt; Going through your article you linked, I found the issue. dfs.client.https.need-auth was set to true in hdfs-site.xml. The error cleared after that and NameNode came up with a valid SSL certificate! You just made my Friday &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 11 Feb 2017 06:18:43 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Issue-with-NameNode-startup-after-enabling-SSL/m-p/170499#M54068</guid>
      <dc:creator>m3l8</dc:creator>
      <dc:date>2017-02-11T06:18:43Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with NameNode startup after enabling SSL</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Issue-with-NameNode-startup-after-enabling-SSL/m-p/170500#M54069</link>
      <description>&lt;P&gt;@&lt;A href="https://community.hortonworks.com/users/15990/m3l8.html"&gt;Michael Locatelli&lt;/A&gt;&lt;A href="https://community.hortonworks.com/users/15990/m3l8.html"&gt; &lt;/A&gt;&lt;/P&gt;&lt;P&gt;thats good to hear , feel free to add me for any SSL issues.&lt;/P&gt;</description>
      <pubDate>Sat, 11 Feb 2017 06:26:13 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Issue-with-NameNode-startup-after-enabling-SSL/m-p/170500#M54069</guid>
      <dc:creator>apappu</dc:creator>
      <dc:date>2017-02-11T06:26:13Z</dc:date>
    </item>
  </channel>
</rss>

