<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question ambari-server sync-ldap no longer working in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/ambari-server-sync-ldap-no-longer-working/m-p/211653#M65994</link>
    <description>&lt;P&gt;I was able to sync LDAP at one point with Ambari. I'm not sure exactly when it broke. The users were synced before it broke all work fine and show up in Ambari as being Type: LDAP. When I try to run ambari-server sync-ldap with either the --existing option or --groups I get the same output complaining about the hostname. I have verified that hostname -f shows the correct FQDN and it matches what is output in the results of the command below.&lt;/P&gt;&lt;P&gt;ambari-server sync-ldap --existing &lt;/P&gt;&lt;P&gt;Using python  /usr/bin/python &lt;/P&gt;&lt;P&gt;Syncing with LDAP... &lt;/P&gt;&lt;P&gt;Enter Ambari Admin login: adminusername &lt;/P&gt;&lt;P&gt;Enter Ambari Admin password: &lt;/P&gt;&lt;P&gt;Syncing existing.ERROR: Exiting with exit code 1. &lt;/P&gt;&lt;P&gt;REASON: Sync event creation failed. Error details: hostname '127.0.0.1' doesn't match u'hiddenhostname.domain.com'&lt;/P&gt;</description>
    <pubDate>Thu, 03 Aug 2017 23:35:38 GMT</pubDate>
    <dc:creator>anorton</dc:creator>
    <dc:date>2017-08-03T23:35:38Z</dc:date>
    <item>
      <title>ambari-server sync-ldap no longer working</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/ambari-server-sync-ldap-no-longer-working/m-p/211653#M65994</link>
      <description>&lt;P&gt;I was able to sync LDAP at one point with Ambari. I'm not sure exactly when it broke. The users were synced before it broke all work fine and show up in Ambari as being Type: LDAP. When I try to run ambari-server sync-ldap with either the --existing option or --groups I get the same output complaining about the hostname. I have verified that hostname -f shows the correct FQDN and it matches what is output in the results of the command below.&lt;/P&gt;&lt;P&gt;ambari-server sync-ldap --existing &lt;/P&gt;&lt;P&gt;Using python  /usr/bin/python &lt;/P&gt;&lt;P&gt;Syncing with LDAP... &lt;/P&gt;&lt;P&gt;Enter Ambari Admin login: adminusername &lt;/P&gt;&lt;P&gt;Enter Ambari Admin password: &lt;/P&gt;&lt;P&gt;Syncing existing.ERROR: Exiting with exit code 1. &lt;/P&gt;&lt;P&gt;REASON: Sync event creation failed. Error details: hostname '127.0.0.1' doesn't match u'hiddenhostname.domain.com'&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2017 23:35:38 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/ambari-server-sync-ldap-no-longer-working/m-p/211653#M65994</guid>
      <dc:creator>anorton</dc:creator>
      <dc:date>2017-08-03T23:35:38Z</dc:date>
    </item>
    <item>
      <title>Re: ambari-server sync-ldap no longer working</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/ambari-server-sync-ldap-no-longer-working/m-p/211654#M65995</link>
      <description>&lt;P&gt;@&lt;A href="https://community.hortonworks.com/users/20204/anorton.html"&gt;Aaron Norton&lt;/A&gt;&lt;/P&gt;&lt;P&gt;What are the host entries in your ambari server /etc/hosts ?&lt;BR /&gt;Is the LDAP server entry correct ?&lt;/P&gt;&lt;P&gt;Please revert&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2017 23:40:39 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/ambari-server-sync-ldap-no-longer-working/m-p/211654#M65995</guid>
      <dc:creator>Shelton</dc:creator>
      <dc:date>2017-08-03T23:40:39Z</dc:date>
    </item>
    <item>
      <title>Re: ambari-server sync-ldap no longer working</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/ambari-server-sync-ldap-no-longer-working/m-p/211655#M65996</link>
      <description>&lt;P style="margin-left: 20px;"&gt;my /etc/hosts file only contains the 2 standard localhost lines. I have verified that both forward and revers DNS works correctly for the Ambari server and the LDAP server. I did try adding both of them into the /etc/hosts file in the format of "IP  FQDN  shortname" and that did not seem to make any difference at all. I looked at the ambari.properties file and it has the correct LDAP hostname in it.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Aug 2017 23:51:23 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/ambari-server-sync-ldap-no-longer-working/m-p/211655#M65996</guid>
      <dc:creator>anorton</dc:creator>
      <dc:date>2017-08-03T23:51:23Z</dc:date>
    </item>
    <item>
      <title>Re: ambari-server sync-ldap no longer working</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/ambari-server-sync-ldap-no-longer-working/m-p/211656#M65997</link>
      <description>&lt;P&gt;I just got the exact same error. And the problem came after
a “yum update” on a Redhat 7 server. I tested the synchronization just before I
upgraded the OS and it worked fine. After the upgrade, I get the same error. I’ll
post an answer once I find a solution to the problem&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2017 19:54:17 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/ambari-server-sync-ldap-no-longer-working/m-p/211656#M65997</guid>
      <dc:creator>berry_osterlund</dc:creator>
      <dc:date>2017-08-23T19:54:17Z</dc:date>
    </item>
    <item>
      <title>Re: ambari-server sync-ldap no longer working</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/ambari-server-sync-ldap-no-longer-working/m-p/211657#M65998</link>
      <description>&lt;P&gt;@Aaron Norton&lt;/P&gt;&lt;P&gt;One way you can work around this problem is to change
"SERVER_API_HOST = '127.0.0.1'" in
/usr/lib/python2.6/site-packages/ambari_server/serverUtils.py so it points to
your server with the full hostname. That will work around the problem with SSL
that we see. &lt;/P&gt;</description>
      <pubDate>Thu, 24 Aug 2017 17:30:45 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/ambari-server-sync-ldap-no-longer-working/m-p/211657#M65998</guid>
      <dc:creator>berry_osterlund</dc:creator>
      <dc:date>2017-08-24T17:30:45Z</dc:date>
    </item>
    <item>
      <title>Re: ambari-server sync-ldap no longer working</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/ambari-server-sync-ldap-no-longer-working/m-p/211658#M65999</link>
      <description>&lt;P&gt;Yes that workaround does work. Will wait for a fix before I Accept the solution.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Aug 2017 19:15:10 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/ambari-server-sync-ldap-no-longer-working/m-p/211658#M65999</guid>
      <dc:creator>anorton</dc:creator>
      <dc:date>2017-08-24T19:15:10Z</dc:date>
    </item>
    <item>
      <title>Re: ambari-server sync-ldap no longer working</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/ambari-server-sync-ldap-no-longer-working/m-p/211659#M66000</link>
      <description>&lt;P&gt;So, the main reason we see this error is because the default
behaviour for ssl cert verification have changed in python. If you take a look
in /etc/python/cert-verification.cfg, you will see that in python-libs-2.7.5-34,
the “verify=disable” value was default. But after upgrade of that package to python-libs-2.7.5-58,
the value is now “verify=platform_default”. And at least in our system, that
means enabled. After changing this back to “verify=disable”, the synchronization
works again without having to do the workaround I wrote about earlier. I have
verified this on a non-upgraded system by changing it to enabled and that also
results in errors for the user synchronization&lt;/P&gt;&lt;P&gt;This error also affect LLAP if you are running that. After upgrade,
LLAP wont start because of cert verifications. You will get a “[SSL:
CERTIFICATE_VERIFY_FAILED] certificate verify failed (_ssl.c:579)” error
message. Changing the verify parameter described above also fixes that problem.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Aug 2017 13:13:39 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/ambari-server-sync-ldap-no-longer-working/m-p/211659#M66000</guid>
      <dc:creator>berry_osterlund</dc:creator>
      <dc:date>2017-08-25T13:13:39Z</dc:date>
    </item>
    <item>
      <title>Re: ambari-server sync-ldap no longer working</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/ambari-server-sync-ldap-no-longer-working/m-p/211660#M66001</link>
      <description>&lt;P&gt;Thanks for the detailed explanation Berry!&lt;/P&gt;</description>
      <pubDate>Fri, 25 Aug 2017 21:46:39 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/ambari-server-sync-ldap-no-longer-working/m-p/211660#M66001</guid>
      <dc:creator>anorton</dc:creator>
      <dc:date>2017-08-25T21:46:39Z</dc:date>
    </item>
  </channel>
</rss>

