<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Nifi / Ranger / Audit to Solr / unable to find valid certification path to requested target in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Nifi-Ranger-Audit-to-Solr-unable-to-find-valid-certification/m-p/149574#M56686</link>
    <description>&lt;P&gt;Glad you got it working!&lt;/P&gt;</description>
    <pubDate>Mon, 13 Mar 2017 23:30:46 GMT</pubDate>
    <dc:creator>bbende</dc:creator>
    <dc:date>2017-03-13T23:30:46Z</dc:date>
    <item>
      <title>Nifi / Ranger / Audit to Solr / unable to find valid certification path to requested target</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Nifi-Ranger-Audit-to-Solr-unable-to-find-valid-certification/m-p/149568#M56680</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have a HDF cluster (kerberos/ ranger) on which the client nodes all reports the following &lt;/P&gt;&lt;PRE&gt;2017-03-09 14:54:00,662 WARN [org.apache.ranger.audit.queue.AuditBatchQueue0] o.a.r.audit.provider.BaseAuditHandler failed to log audit event: {"repoType":10,"repo":"&amp;lt;MASKED&amp;gt;","reqUser":"&amp;lt;MASKED&amp;gt;","evtTime":"2017-03-09 14:54:00.275","access":"WRITE","resource":"/proxy","resType":"nifi-resource","action":"WRITE","result":1,"policy":2,"enforcer":"ranger-acl","cliIP":"&amp;lt;MASKED&amp;gt;","agentHost":"&amp;lt;MASKED&amp;gt;","logType":"RangerAudit","id":"56f7f5c4-a834-4405-9bae-18b19453129d-140","seq_num":276,"event_count":1,"event_dur_ms":0,"tags":[]}
org.apache.solr.client.solrj.impl.CloudSolrClient$RouteException: IOException occured when talking to server at: &lt;A href="https://&amp;lt;Ambari_solr_FQDN&amp;gt;:8886/solr/ranger_audits_shard1_replica1" target="_blank"&gt;https://&amp;lt;Ambari_solr_FQDN&amp;gt;:8886/solr/ranger_audits_shard1_replica1&lt;/A&gt;
        at org.apache.solr.client.solrj.impl.CloudSolrClient.directUpdate(CloudSolrClient.java:634) ~[solr-solrj-5.5.1.jar:5.5.1
				&amp;lt;SNIP&amp;gt;
Caused by: org.apache.solr.client.solrj.SolrServerException: IOException occured when talking to server at: &lt;A href="https://&amp;lt;Ambari_solr_FQDN&amp;gt;:8886/solr/ranger_audits_shard1_replica1" target="_blank"&gt;https://&amp;lt;Ambari_solr_FQDN&amp;gt;:8886/solr/ranger_audits_shard1_replica1&lt;/A&gt;
        &amp;lt;SNIP&amp;gt;
Caused by: javax.net.ssl.SSLHandshakeException: sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
        &amp;lt;SNIP&amp;gt;
Caused by: sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
        &amp;lt;SNIP&amp;gt;
Caused by: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
        &amp;lt;SNIP&amp;gt;
&lt;/PRE&gt;&lt;P&gt;I have checked the keystore &amp;amp; truststore storead at the location refered in Ambari: the chain looks correct to me.&lt;/P&gt;&lt;P&gt;curl &lt;A href="https://&amp;lt;Ambari_solr_FQDN&amp;gt;:8886/solr/ranger_audits_shard1_replica1" target="_blank"&gt;https://&amp;lt;Ambari_solr_FQDN&amp;gt;:8886/solr/ranger_audits_shard1_replica1&lt;/A&gt; connects without errors &lt;/P&gt;&lt;P&gt;openssl indicates a valid chain.&lt;/P&gt;&lt;P&gt;I can't find which store / chain is used by Nifi and how to fix this.&lt;/P&gt;&lt;P&gt;Any help will be welcome.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Christophe&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2017 22:39:26 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Nifi-Ranger-Audit-to-Solr-unable-to-find-valid-certification/m-p/149568#M56680</guid>
      <dc:creator>ChrisV</dc:creator>
      <dc:date>2017-03-09T22:39:26Z</dc:date>
    </item>
    <item>
      <title>Re: Nifi / Ranger / Audit to Solr / unable to find valid certification path to requested target</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Nifi-Ranger-Audit-to-Solr-unable-to-find-valid-certification/m-p/149569#M56681</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/16129/cvico.html" nodeid="16129"&gt;@Christophe  Vico&lt;/A&gt; &lt;/P&gt;&lt;P&gt;This appears to be an issue between Ranger and Solr and have nothing to do with NiFi at all.  I suggest updating your tags on this post to include Solr.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2017 23:11:16 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Nifi-Ranger-Audit-to-Solr-unable-to-find-valid-certification/m-p/149569#M56681</guid>
      <dc:creator>MattWho</dc:creator>
      <dc:date>2017-03-09T23:11:16Z</dc:date>
    </item>
    <item>
      <title>Re: Nifi / Ranger / Audit to Solr / unable to find valid certification path to requested target</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Nifi-Ranger-Audit-to-Solr-unable-to-find-valid-certification/m-p/149570#M56682</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/525/mclark.html" nodeid="525"&gt;@Matt Clarke&lt;/A&gt; thanks. I update the tags, I was not too sure actually where to submit this.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2017 23:34:44 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Nifi-Ranger-Audit-to-Solr-unable-to-find-valid-certification/m-p/149570#M56682</guid>
      <dc:creator>ChrisV</dc:creator>
      <dc:date>2017-03-09T23:34:44Z</dc:date>
    </item>
    <item>
      <title>Re: Nifi / Ranger / Audit to Solr / unable to find valid certification path to requested target</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Nifi-Ranger-Audit-to-Solr-unable-to-find-valid-certification/m-p/149571#M56683</link>
      <description>&lt;P&gt;I believe this is an issue between the truststore used by the plugin and certificates used by Solr... basically the SSL handshake believes that the certificate Solr is using is not trusted by whatever is in the truststore that the plugin is using.&lt;/P&gt;&lt;P&gt;How did you enable SSL on Solr? Did you generate your own certificate and do this manually?&lt;/P&gt;&lt;P&gt;The Ranger plugin that runs inside the NiFi JVM process (which is what sends the audits to Solr) will use the values of xasecure.policymgr.clientssl.truststore, xasecure.policymgr.clientssl.truststore.password, and xasecure.policymgr.clientssl.truststore.credential.file which come from ranger-nifi-policymgr-ssl.xml&lt;/P&gt;&lt;P&gt;So the truststore specified there needs to trust the certificate authority that created the cert that Solr is using.&lt;/P&gt;&lt;P&gt;Also, this issue could be related, but not sure:&lt;/P&gt;&lt;P&gt;&lt;A href="https://issues.apache.org/jira/browse/RANGER-1216" target="_blank"&gt;https://issues.apache.org/jira/browse/RANGER-1216&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Looks like it was fixed for Ranger 0.7, but I believe HDF is using 0.6.x.&lt;/P&gt;</description>
      <pubDate>Sat, 11 Mar 2017 01:37:56 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Nifi-Ranger-Audit-to-Solr-unable-to-find-valid-certification/m-p/149571#M56683</guid>
      <dc:creator>bbende</dc:creator>
      <dc:date>2017-03-11T01:37:56Z</dc:date>
    </item>
    <item>
      <title>Re: Nifi / Ranger / Audit to Solr / unable to find valid certification path to requested target</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Nifi-Ranger-Audit-to-Solr-unable-to-find-valid-certification/m-p/149572#M56684</link>
      <description>&lt;P&gt;@bryan bende&lt;/P&gt;&lt;P&gt;Thanks for answers.&lt;/P&gt;&lt;P&gt;The truststore &amp;amp; keystore listed in the Nifi configuration (xasecure.policymgr.clientssl.*) are the one I checked, containing the right certificates as far a I can tell. The trustore.jks does contain the root CA used to issue the certificates&lt;/P&gt;&lt;P&gt;I have again rechecked, and made sure that nifi:hadoop was onwer of the stores, but to no luck.&lt;/P&gt;&lt;P&gt;I don't think the JIRa is linked, as in my case, I don;t establish the SSL connection, so I can't possibly yet be impacted by Kerberos&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Sat, 11 Mar 2017 03:48:07 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Nifi-Ranger-Audit-to-Solr-unable-to-find-valid-certification/m-p/149572#M56684</guid>
      <dc:creator>ChrisV</dc:creator>
      <dc:date>2017-03-11T03:48:07Z</dc:date>
    </item>
    <item>
      <title>Re: Nifi / Ranger / Audit to Solr / unable to find valid certification path to requested target</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Nifi-Ranger-Audit-to-Solr-unable-to-find-valid-certification/m-p/149573#M56685</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I found the cause of this one : the keystore was specified as truststore for Ranger plugin. I missed it while reviewing the configs.&lt;/P&gt;&lt;P&gt;Thanks &lt;A rel="user" href="https://community.cloudera.com/users/363/bbende.html" nodeid="363"&gt;@Bryan Bende&lt;/A&gt;!&lt;/P&gt;</description>
      <pubDate>Mon, 13 Mar 2017 23:18:25 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Nifi-Ranger-Audit-to-Solr-unable-to-find-valid-certification/m-p/149573#M56685</guid>
      <dc:creator>ChrisV</dc:creator>
      <dc:date>2017-03-13T23:18:25Z</dc:date>
    </item>
    <item>
      <title>Re: Nifi / Ranger / Audit to Solr / unable to find valid certification path to requested target</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Nifi-Ranger-Audit-to-Solr-unable-to-find-valid-certification/m-p/149574#M56686</link>
      <description>&lt;P&gt;Glad you got it working!&lt;/P&gt;</description>
      <pubDate>Mon, 13 Mar 2017 23:30:46 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Nifi-Ranger-Audit-to-Solr-unable-to-find-valid-certification/m-p/149574#M56686</guid>
      <dc:creator>bbende</dc:creator>
      <dc:date>2017-03-13T23:30:46Z</dc:date>
    </item>
  </channel>
</rss>

