<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Issue After enabling the TLS level 1 encryption in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Issue-After-enabling-the-TLS-level-1-encryption/m-p/58946#M66723</link>
    <description>&lt;P&gt;This issue resolved for me when I rebooted my CM machine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Amit&lt;/P&gt;</description>
    <pubDate>Thu, 17 Aug 2017 08:13:10 GMT</pubDate>
    <dc:creator>AmitAdhau</dc:creator>
    <dc:date>2017-08-17T08:13:10Z</dc:date>
    <item>
      <title>Issue After enabling the TLS level 1 encryption</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Issue-After-enabling-the-TLS-level-1-encryption/m-p/58907#M66720</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have enabled the TLS level 1 encryption and after the same I am getting few errors in my log as per below;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1] Getting below error in My cloudera-scm-server.log&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2017-08-16 14:56:56,261 INFO MainThread:com.cloudera.server.cmf.WebServerImpl: Cipher suite TLS_EMPTY_RENEGOTIATION_INFO_SCSV found. Allowing SSL/TLS renegotiations.&lt;BR /&gt;2017-08-16 14:56:56,288 INFO MainThread:com.cloudera.server.cmf.WebServerImpl: TLS web connections will use port: 7183&lt;BR /&gt;2017-08-16 14:56:56,292 INFO MainThread:com.cloudera.server.cmf.WebServerImpl: Plaintext web connections will use port: 7180&lt;BR /&gt;2017-08-16 14:56:56,337 INFO MainThread:com.cloudera.cmf.service.ServiceHandlerRegistry: Executing command GenerateCredentials BasicCmdArgs{args=[]}.&lt;BR /&gt;2017-08-16 14:56:56,337 INFO MainThread:com.cloudera.server.cmf.Main: Generating credentials (command 4481) at startup&lt;BR /&gt;2017-08-16 14:56:56,393 INFO WebServerImpl:com.cloudera.enterprise.JavaMelodyFacade: No JavaMelody class net.bull.javamelody.SessionListener: net.bull.javamelody.SessionListener&lt;BR /&gt;2017-08-16 14:56:56,479 ERROR ParcelUpdateService:com.cloudera.parcel.components.ParcelDownloaderImpl: Unable to retrieve remote parcel repository manifest&lt;BR /&gt;java.util.concurrent.ExecutionException: java.net.ConnectException: Connection refused to http://serverip:8000/manifest.json&lt;BR /&gt;at com.ning.http.client.providers.netty.NettyResponseFuture.abort(NettyResponseFuture.java:297)&lt;BR /&gt;at com.ning.http.client.providers.netty.NettyConnectListener.operationComplete(NettyConnectListener.java:104)&lt;BR /&gt;at org.jboss.netty.channel.DefaultChannelFuture.notifyListener(DefaultChannelFuture.java:399)&lt;BR /&gt;at org.jboss.netty.channel.DefaultChannelFuture.notifyListeners(DefaultChannelFuture.java:390)&lt;BR /&gt;at org.jboss.netty.channel.DefaultChannelFuture.setFailure(DefaultChannelFuture.java:352)&lt;BR /&gt;at org.jboss.netty.channel.socket.nio.NioClientSocketPipelineSink$Boss.connect(NioClientSocketPipelineSink.java:409)&lt;BR /&gt;at org.jboss.netty.channel.socket.nio.NioClientSocketPipelineSink$Boss.processSelectedKeys(NioClientSocketPipelineSink.java:366)&lt;BR /&gt;at org.jboss.netty.channel.socket.nio.NioClientSocketPipelineSink$Boss.run(NioClientSocketPipelineSink.java:282)&lt;BR /&gt;at org.jboss.netty.util.ThreadRenamingRunnable.run(ThreadRenamingRunnable.java:102)&lt;BR /&gt;at org.jboss.netty.util.internal.DeadLockProofWorker$1.run(DeadLockProofWorker.java:42)&lt;BR /&gt;at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1145)&lt;BR /&gt;at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:615)&lt;BR /&gt;at java.lang.Thread.run(Thread.java:745)&lt;BR /&gt;Caused by: java.net.ConnectException: Connection refused to http://serverip:8000/manifest.json&lt;BR /&gt;at com.ning.http.client.providers.netty.NettyConnectListener.operationComplete(NettyConnectListener.java:100)&lt;BR /&gt;... 11 more&lt;BR /&gt;Caused by: java.net.ConnectException: Connection refused&lt;BR /&gt;at sun.nio.ch.SocketChannelImpl.checkConnect(Native Method)&lt;BR /&gt;at sun.nio.ch.SocketChannelImpl.finishConnect(SocketChannelImpl.java:739)&lt;BR /&gt;at org.jboss.netty.channel.socket.nio.NioClientSocketPipelineSink$Boss.connect(NioClientSocketPipelineSink.java:404)&lt;BR /&gt;at org.jboss.netty.channel.socket.nio.NioClientSocketPipelineSink$Boss.processSelectedKeys(NioClientSocketPipelineSink.java:366)&lt;BR /&gt;at org.jboss.netty.channel.socket.nio.NioClientSocketPipelineSink$Boss.run(NioClientSocketPipelineSink.java:282)&lt;BR /&gt;... 3 more&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2017-08-16 15:31:35,624 INFO 1922557741@scm-web-39:com.cloudera.server.web.cmf.AuthenticationFailureEventListener: Authentication failure for user: '__cloudera_internal_user__mgmt-EVENTSERVER-bdec96eb8ea18d0be431197fa05f0a3b' from CMhost&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2] Getting below error in my cloudera-scm-agent.log&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ERROR &amp;nbsp; &amp;nbsp;Heartbeating to CMhostname:7182 failed. Connection refused&lt;/P&gt;&lt;P&gt;Traceback (most recent call last):&lt;BR /&gt;File "/usr/lib64/cmf/agent/build/env/lib/python2.6/site-packages/cmf-5.9.1-py2.6.egg/cmf/agent.py", line 1346, in _send_heartbeat&lt;BR /&gt;self.max_cert_depth)&lt;BR /&gt;File "/usr/lib64/cmf/agent/build/env/lib/python2.6/site-packages/cmf-5.9.1-py2.6.egg/cmf/https.py", line 132, in __init__&lt;BR /&gt;self.conn.connect()&lt;BR /&gt;File "/usr/lib64/cmf/agent/build/env/lib/python2.6/site-packages/M2Crypto-0.21.1-py2.6-linux-x86_64.egg/M2Crypto/httpslib.py", line 50, in connect&lt;BR /&gt;self.sock.connect((self.host, self.port))&lt;BR /&gt;File "/usr/lib64/cmf/agent/build/env/lib/python2.6/site-packages/M2Crypto-0.21.1-py2.6-linux-x86_64.egg/M2Crypto/SSL/Connection.py", line 181, in connect&lt;BR /&gt;self.socket.connect(addr)&lt;BR /&gt;File "&amp;lt;string&amp;gt;", line 1, in connect&lt;BR /&gt;error: [Errno 111] Connection refused&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ERROR &amp;nbsp; &amp;nbsp;[1646-cloudera-mgmt-HOSTMONITOR] Failed to update&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3] In Eventserver log file&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2017-08-16 13:28:30,475 ERROR com.cloudera.cmf.eventcatcher.server.EventCatcherService: Error starting EventServer&lt;BR /&gt;org.apache.lucene.store.LockObtainFailedException: Lock obtain timed out: NativeFSLock@/var/lib/cloudera-scm-eventserver/v3/write.lock&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anybody please help me on the same, as I am not able to find out the proper solution for the same.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Amit&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Aug 2017 15:38:48 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Issue-After-enabling-the-TLS-level-1-encryption/m-p/58907#M66720</guid>
      <dc:creator>AmitAdhau</dc:creator>
      <dc:date>2017-08-16T15:38:48Z</dc:date>
    </item>
    <item>
      <title>Re: Issue After enabling the TLS level 1 encryption</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Issue-After-enabling-the-TLS-level-1-encryption/m-p/58912#M66721</link>
      <description>Did you do these steps prior to Level 1?&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://www.cloudera.com/documentation/enterprise/5-8-x/topics/cm_sg_tls_browser.html#xd_583c10bfdbd326ba-7dae4aa6-147c30d0933--7a61" target="_blank"&gt;https://www.cloudera.com/documentation/enterprise/5-8-x/topics/cm_sg_tls_browser.html#xd_583c10bfdbd326ba-7dae4aa6-147c30d0933--7a61&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Did you check that your keystore contains the CM certificate and has the correct hostname?&lt;BR /&gt;Is the keystore file readable by the CM process user?&lt;BR /&gt;</description>
      <pubDate>Wed, 16 Aug 2017 16:21:55 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Issue-After-enabling-the-TLS-level-1-encryption/m-p/58912#M66721</guid>
      <dc:creator>mbigelow</dc:creator>
      <dc:date>2017-08-16T16:21:55Z</dc:date>
    </item>
    <item>
      <title>Re: Issue After enabling the TLS level 1 encryption</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Issue-After-enabling-the-TLS-level-1-encryption/m-p/58919#M66722</link>
      <description>&lt;P&gt;Thanks mbigelow,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="login-bold"&gt;Yes, I have&amp;nbsp;added the public CA certificate to keystore and&amp;nbsp;I have given the user cloudera-scm a full permission on the keystore files like cacerts,jsscacerts, pki folder, x509 folder and jks folder.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="login-bold"&gt;I have validated the certificate using commands;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="login-bold"&gt;openssl s_client -showcerts -connect hostname:443&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="login-bold"&gt;And&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="login-bold"&gt;keytool -list -v -keystore cacerts --alias&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="login-bold"&gt;I have also validated that in the cloudera agent process file&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="login-bold"&gt;/var/run/cloudera-scm-agent/process/1653-cloudera-mgmt-SERVICEMONITOR/cmon.conf&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="login-bold"&gt;I can see some of the ssl entries as per below;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;lt;property&amp;gt;&lt;BR /&gt;&amp;lt;name&amp;gt;scm.server.url&amp;lt;/name&amp;gt;&lt;BR /&gt;&amp;lt;value&amp;gt;https://hostname:7183&amp;lt;/value&amp;gt;&lt;BR /&gt;&amp;lt;/property&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;lt;property&amp;gt;&lt;BR /&gt;&amp;lt;name&amp;gt;com.cloudera.enterprise.ssl.client.truststore.location&amp;lt;/name&amp;gt;&lt;BR /&gt;&amp;lt;value&amp;gt;/usr/java/jdk1.7.0_67-cloudera/jre/lib/security/cacerts&amp;lt;/value&amp;gt;&lt;BR /&gt;&amp;lt;/property&amp;gt;&lt;BR /&gt;&amp;lt;property&amp;gt;&lt;BR /&gt;&amp;lt;name&amp;gt;com.cloudera.enterprise.ssl.client.truststore.password&amp;lt;/name&amp;gt;&lt;BR /&gt;&amp;lt;value&amp;gt;changeit&amp;lt;/value&amp;gt;&lt;BR /&gt;&amp;lt;/property&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regarding your point "&lt;SPAN&gt;correct hostname in certificate" do I need to verify anything else, apart from what I mentioned above.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Also, I would be really thankful if you can suggest, what&amp;nbsp;else I can do to fix these errors.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Amit&lt;/P&gt;</description>
      <pubDate>Wed, 16 Aug 2017 18:09:34 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Issue-After-enabling-the-TLS-level-1-encryption/m-p/58919#M66722</guid>
      <dc:creator>AmitAdhau</dc:creator>
      <dc:date>2017-08-16T18:09:34Z</dc:date>
    </item>
    <item>
      <title>Re: Issue After enabling the TLS level 1 encryption</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Issue-After-enabling-the-TLS-level-1-encryption/m-p/58946#M66723</link>
      <description>&lt;P&gt;This issue resolved for me when I rebooted my CM machine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Amit&lt;/P&gt;</description>
      <pubDate>Thu, 17 Aug 2017 08:13:10 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Issue-After-enabling-the-TLS-level-1-encryption/m-p/58946#M66723</guid>
      <dc:creator>AmitAdhau</dc:creator>
      <dc:date>2017-08-17T08:13:10Z</dc:date>
    </item>
    <item>
      <title>Re: Issue After enabling the TLS level 1 encryption</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Issue-After-enabling-the-TLS-level-1-encryption/m-p/86464#M66724</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/17440"&gt;@AmitAdhau&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you kindly help me out with steps to deploy tls using self-signed certificate.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Feb 2019 10:18:32 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Issue-After-enabling-the-TLS-level-1-encryption/m-p/86464#M66724</guid>
      <dc:creator>prabhat10</dc:creator>
      <dc:date>2019-02-14T10:18:32Z</dc:date>
    </item>
  </channel>
</rss>

