09-11-2018 09:01 AM
i have renewed the tls certificates and applied on the cloudera manager server but the browser is still showing the older one by looking at the expiry date , tried clearing the browser cache , but still it shows older ones. appreciate for any help
09-11-2018 10:33 AM
09-11-2018 10:46 AM
09-11-2018 11:03 AM
openssl s_client connect is reading the old certificate ,whereas i have replaced ceritificates with new one under the /opt/cloudera/security/x509 and /opt/cloudera/security/jks path
and i did not happen to notice any heartbeat issue , agents hearbeat are also working fine , i don't see any issues with that
09-11-2018 11:14 AM
Yes of course.Restart the scm and agents.Then two things can happen:
- everything falls apart - your agents will not be able to communicate with the scm server
- all ok - check your certificate with openssl - if it is still old, you are configuing the certificate in the wrong path.
Check also your settings in /etc.
09-11-2018 11:18 AM
it should have fallen apart after 15 secs, thats interval at which agents sends heartbeat and i have encountered issues with TLS over the past and when somethig has gone wrong , service would immediately fail and throws error in the log.
this is quite weird though
09-11-2018 11:28 AM