<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Cloudera Manager using SSL failed, how to revert changes? in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Cloudera-Manager-using-SSL-failed-how-to-revert-changes/m-p/80193#M83692</link>
    <description>&lt;P&gt;Bgooley,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your reply and vast explanation how to roll back an failed TLS configuration. It did the trick and I can go on. A new challenge arose, correct certificates within an own keystore. But for now I am totally happy to have a workaround to get / keep Cloudera alive when failing TLS.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;AadD&lt;/P&gt;</description>
    <pubDate>Fri, 21 Sep 2018 14:54:17 GMT</pubDate>
    <dc:creator>AadD</dc:creator>
    <dc:date>2018-09-21T14:54:17Z</dc:date>
    <item>
      <title>Cloudera Manager using SSL failed, how to revert changes?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Cloudera-Manager-using-SSL-failed-how-to-revert-changes/m-p/80106#M83689</link>
      <description>&lt;P&gt;Dear Community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My first post here and experiencing my first carefull steps into the world of Cloudera. But during confguration I messed up. Using the installation guide of Cloudera Manager version 6.0x I followed the steps to get the admin GUI only entered via HTTPS. After restarting the Cloudera server I can not enter the admin GUI via port 7183 and of course not anymore on port 7180. I read a lot about reverting changes to get into the GUI again but all solutions regarding entering the embedded postgress database which I can, but any changes I try to make ends into errors like "relation.... does not exists". My question is how I can revert TLS / SSL changes so I can enter the administration GUI again. As a beginner I think I need to a more detailed explanation then for example delete from CONFIGS where ATTR='TLS setting' or something like that, a big sorry for that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance and kind regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;AadD&lt;/P&gt;</description>
      <pubDate>Thu, 20 Sep 2018 13:21:39 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Cloudera-Manager-using-SSL-failed-how-to-revert-changes/m-p/80106#M83689</guid>
      <dc:creator>AadD</dc:creator>
      <dc:date>2018-09-20T13:21:39Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudera Manager using SSL failed, how to revert changes?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Cloudera-Manager-using-SSL-failed-how-to-revert-changes/m-p/80108#M83690</link>
      <description>&lt;P&gt;Dear community,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Update: I managed to get the queries like delete from configs where ATTR='xxxx_tls' but after restart I still can not reach the Cloudera Manager portal. What do I need to do to get really inverted the SSL configuration so I can enter the portal with port 7180 and HTTP again?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance and kind regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;AadD&lt;/P&gt;</description>
      <pubDate>Thu, 20 Sep 2018 14:39:14 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Cloudera-Manager-using-SSL-failed-how-to-revert-changes/m-p/80108#M83690</guid>
      <dc:creator>AadD</dc:creator>
      <dc:date>2018-09-20T14:39:14Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudera Manager using SSL failed, how to revert changes?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Cloudera-Manager-using-SSL-failed-how-to-revert-changes/m-p/80109#M83691</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/29417"&gt;@AadD&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for trying out Cloudera; sorry that it has been a rocky start, but you came to the right place for help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We'll need some information in order to assist:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- What steps did you follow to intall? What documentation? (list specific URLs if you can)&lt;/P&gt;&lt;P&gt;- What steps did you follow to enable TLS? (list specific URLs if you can)&lt;/P&gt;&lt;P&gt;- Did Cloudera Manager ever start and allow you to access it on port 7180? (http://cm_host:7180?)&lt;/P&gt;&lt;P&gt;- How do you know that Cloudera Manager running or responding to HTTP requests?&amp;nbsp; What did you do to test?&lt;/P&gt;&lt;P&gt;- If you ssh to the host where Cloudera Manager should be running, is it listening on port 7180?&amp;nbsp; 7183? 7182?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Run:&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;# netstat -nap |grep 7180;netstat -nap |grep 7183; netstat -nap |grep 7182&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- If the problem is with TLS, then the following steps will turn off the TLS port for the Cloudera Manager User Interface:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(1)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Review your Cloudera Manager database configuration:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;# cat /etc/cloudera-scm-server/db.properties&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(2)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Use the information in &lt;STRONG&gt;db.properties&lt;/STRONG&gt; to run the psql command:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example, this is how I would connect on my host:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- I see the following in db.properties:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;com.cloudera.cmf.db.type=postgresql&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;com.cloudera.cmf.db.host=localhost:7432&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;com.cloudera.cmf.db.name=scm&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;com.cloudera.cmf.db.user=scm&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;com.cloudera.cmf.db.password=FpZ3wh9LFT&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;com.cloudera.cmf.db.setupType=EMBEDDED&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(3)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Use the &lt;STRONG&gt;db.properties&lt;/STRONG&gt; information to connect to your database&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Based on the information in my environment, that would be:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;# &lt;STRONG&gt;psql -U scm -h localhost -p 7432&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Password for user scm: &lt;STRONG&gt;&lt;FONT color="#3366FF"&gt;FpZ3wh9LFT&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;psql (9.2.18)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Type "help" for help.&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;scm=&amp;gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(4)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Check the configuration that governs TLS for Cloudera Manager and Cloudera Manager agent communication:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;scm=&amp;gt; select * from configs where attr = 'web_tls';&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;scm=&amp;gt; select * from configs where attr = 'agent_tls';&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(5)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If any rows are returned from the above commands, delete them:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;scm=&amp;gt; delete from configs where attr = 'web_tls';&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;scm=&amp;gt; delete from configs wehre attr = 'agent_tls';&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Search again to verify that no rows are returned:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;scm=&amp;gt; select * from configs where attr = 'web_tls';&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;scm=&amp;gt; select * from configs where attr = 'agent_tls';&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(6)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If there are no rows returned, restart Cloudera Manager with:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;# service cloudera-scm-server restart&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(7)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;CM can take minutes to start, so wait about 5 to be sure and then run the netstats again.&lt;/P&gt;&lt;P&gt;If you see that CM is listening on port 7182 (agent communication) and 7180 (non-tls web ui) then try accessing it via your browser.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If CM still fails to start, review the Cloudera Manager log.&lt;/P&gt;&lt;P&gt;On the Cloudera Manager host it is by default:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;/var/log/cloudera-scm-server/cloudera-scm-server.log&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let us know how it goes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ben&lt;/P&gt;</description>
      <pubDate>Thu, 20 Sep 2018 15:26:38 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Cloudera-Manager-using-SSL-failed-how-to-revert-changes/m-p/80109#M83691</guid>
      <dc:creator>bgooley</dc:creator>
      <dc:date>2018-09-20T15:26:38Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudera Manager using SSL failed, how to revert changes?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Cloudera-Manager-using-SSL-failed-how-to-revert-changes/m-p/80193#M83692</link>
      <description>&lt;P&gt;Bgooley,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your reply and vast explanation how to roll back an failed TLS configuration. It did the trick and I can go on. A new challenge arose, correct certificates within an own keystore. But for now I am totally happy to have a workaround to get / keep Cloudera alive when failing TLS.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;AadD&lt;/P&gt;</description>
      <pubDate>Fri, 21 Sep 2018 14:54:17 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Cloudera-Manager-using-SSL-failed-how-to-revert-changes/m-p/80193#M83692</guid>
      <dc:creator>AadD</dc:creator>
      <dc:date>2018-09-21T14:54:17Z</dc:date>
    </item>
    <item>
      <title>Re: Cloudera Manager using SSL failed, how to revert changes?</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Cloudera-Manager-using-SSL-failed-how-to-revert-changes/m-p/80198#M83693</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/29417"&gt;@AadD&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you can post the command(s) you used to create the CM private key and cert that would help.&lt;/P&gt;&lt;P&gt;Also, if you can share the output for &lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;keytool -list -v -keystore &amp;lt;keystore&amp;gt;&lt;/FONT&gt;&lt;/STRONG&gt; that could help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Generally, if the server won't start at all, there is a problem with a password or permissions on the JKS file you are using for your Key file or truststore.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When implementing for the first time, only enable TLS for the CM admin console (UI).&amp;nbsp; If there is a problem using a certificate, it should start up using non-tls and warn you that something's wrong.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Check &lt;FONT face="courier new,courier"&gt;/var/log/cloudera-scm-server/cloudera-scm-server.log&lt;/FONT&gt; for exceptions or messages pertaining to SSL/TLS.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ben&lt;/P&gt;</description>
      <pubDate>Fri, 21 Sep 2018 19:23:29 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Cloudera-Manager-using-SSL-failed-how-to-revert-changes/m-p/80198#M83693</guid>
      <dc:creator>bgooley</dc:creator>
      <dc:date>2018-09-21T19:23:29Z</dc:date>
    </item>
  </channel>
</rss>

