<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question After enabling HTTPS to CM, monitors stopped working in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/After-enabling-HTTPS-to-CM-monitors-stopped-working/m-p/51370#M55275</link>
    <description>&lt;P&gt;After configuring TLS with self-signed certificates up to "Step 2: Enable HTTPS for the Cloudera Manager Admin Console and Specify Server Keystore Properties", various CM monitoring services stopped working: Activity Monitor, Even Server, Host Monitor, Reports Manager, Service Monitor. Is it normal?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The log /var/log/cloudera-scm-eventserver/mgmt-cmf-mgmt-EVENTSERVER-md01.rcc.local.log.out says:&lt;/P&gt;&lt;P&gt;======&lt;/P&gt;&lt;P&gt;Failed to publish event: SimpleEvent{attributes={ROLE_TYPE=[EVENTSERVER], EXCEPTION_TYPES=[javax.net.ssl.SSLHandshakeException, sun.security.validator.ValidatorException, sun.security.provider.certpath.SunCertPathBuilderException], HOST_IDS=[21488217-80d2-404d-8ae9-061472dc8314], STACKTRACE=[javax.net.ssl.SSLHandshakeException: sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; at sun.security.ssl.Alerts.getSSLException(Alerts.java:192)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; at sun.security.ssl.SSLSocketImpl.fatal(SSLSocketImpl.java:1949)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; at sun.security.ssl.Handshaker.fatalSE(Handshaker.java:302)&lt;BR /&gt;======&lt;/P&gt;&lt;P&gt;I guess, it means that each host needs to know where to find its keystore (during the first 2 steps the path was only given for CM host)? Would this be solved in the next Level 1 steps when agents are configured or do I need to fix it somehow now before proceeding to the next steps? For example, provide a path to a truststore (which would be the same for all the hosts? during the configuration I only provided a path to the keystore on CM machine and its password).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The web login to CM indeed became https. I have not tested the rest of the services but CM shows green status for all of them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;&amp;nbsp;&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 23 Feb 2017 05:24:51 GMT</pubDate>
    <dc:creator>IgorYakushin</dc:creator>
    <dc:date>2017-02-23T05:24:51Z</dc:date>
    <item>
      <title>After enabling HTTPS to CM, monitors stopped working</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/After-enabling-HTTPS-to-CM-monitors-stopped-working/m-p/51370#M55275</link>
      <description>&lt;P&gt;After configuring TLS with self-signed certificates up to "Step 2: Enable HTTPS for the Cloudera Manager Admin Console and Specify Server Keystore Properties", various CM monitoring services stopped working: Activity Monitor, Even Server, Host Monitor, Reports Manager, Service Monitor. Is it normal?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The log /var/log/cloudera-scm-eventserver/mgmt-cmf-mgmt-EVENTSERVER-md01.rcc.local.log.out says:&lt;/P&gt;&lt;P&gt;======&lt;/P&gt;&lt;P&gt;Failed to publish event: SimpleEvent{attributes={ROLE_TYPE=[EVENTSERVER], EXCEPTION_TYPES=[javax.net.ssl.SSLHandshakeException, sun.security.validator.ValidatorException, sun.security.provider.certpath.SunCertPathBuilderException], HOST_IDS=[21488217-80d2-404d-8ae9-061472dc8314], STACKTRACE=[javax.net.ssl.SSLHandshakeException: sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; at sun.security.ssl.Alerts.getSSLException(Alerts.java:192)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; at sun.security.ssl.SSLSocketImpl.fatal(SSLSocketImpl.java:1949)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; at sun.security.ssl.Handshaker.fatalSE(Handshaker.java:302)&lt;BR /&gt;======&lt;/P&gt;&lt;P&gt;I guess, it means that each host needs to know where to find its keystore (during the first 2 steps the path was only given for CM host)? Would this be solved in the next Level 1 steps when agents are configured or do I need to fix it somehow now before proceeding to the next steps? For example, provide a path to a truststore (which would be the same for all the hosts? during the configuration I only provided a path to the keystore on CM machine and its password).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The web login to CM indeed became https. I have not tested the rest of the services but CM shows green status for all of them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;&amp;nbsp;&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Feb 2017 05:24:51 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/After-enabling-HTTPS-to-CM-monitors-stopped-working/m-p/51370#M55275</guid>
      <dc:creator>IgorYakushin</dc:creator>
      <dc:date>2017-02-23T05:24:51Z</dc:date>
    </item>
    <item>
      <title>Re: After enabling HTTPS to CM, monitors stopped working</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/After-enabling-HTTPS-to-CM-monitors-stopped-working/m-p/51402#M55276</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/20381"&gt;@IgorYakushin&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After enabling TLS for the Cloudera Manager UI, the management services will need to know where to find trust for the signer of Cloudera Manager's Certificate. &amp;nbsp;The management service roles contact Cloudera Manager to download information regarding the cluster, so if that information cannot be downloaded, the management service roles will fail.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To configure the truststore used by the Management Service roles, see this documentaiton:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cloudera.com/documentation/enterprise/latest/topics/how_to_configure_cm_tls.html#xd_583c10bfdbd326ba-7dae4aa6-147c30d0933--7a61" target="_blank"&gt;https://www.cloudera.com/documentation/enterprise/latest/topics/how_to_configure_cm_tls.html#xd_583c10bfdbd326ba-7dae4aa6-147c30d0933--7a61&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(you need to perform steps 2 and 3 in the &lt;STRONG&gt;Enable HTTPS for the Cloudera Manager Admin Console&lt;/STRONG&gt; section)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ben&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Feb 2017 21:00:56 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/After-enabling-HTTPS-to-CM-monitors-stopped-working/m-p/51402#M55276</guid>
      <dc:creator>bgooley</dc:creator>
      <dc:date>2017-02-23T21:00:56Z</dc:date>
    </item>
    <item>
      <title>Re: After enabling HTTPS to CM, monitors stopped working</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/After-enabling-HTTPS-to-CM-monitors-stopped-working/m-p/51406#M55277</link>
      <description>&lt;P&gt;Thank you Ben. That worked.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Apparently I was reading older version of the documention where Step 3 (letting CM know where truststore is) is not mentioned. I tried to put it on the same web page where keystore was and that did not work. I did not realize there is yet another page to specify truststore.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Igor&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Feb 2017 21:32:00 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/After-enabling-HTTPS-to-CM-monitors-stopped-working/m-p/51406#M55277</guid>
      <dc:creator>IgorYakushin</dc:creator>
      <dc:date>2017-02-23T21:32:00Z</dc:date>
    </item>
  </channel>
</rss>

