You are viewing a plain text version of this content. The canonical link for it is here.
Posted to issues@nifi.apache.org by "Mark Payne (Jira)" <ji...@apache.org> on 2021/09/21 18:15:00 UTC

[jira] [Resolved] (NIFI-4171) NIFI service wont start on secure cluster

     [ https://issues.apache.org/jira/browse/NIFI-4171?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Mark Payne resolved NIFI-4171.
------------------------------
    Resolution: Not A Bug

This does not appear to be an issue with NiFi - the provided output is from a Python script, which is not part of NiFi.

> NIFI service wont start on secure cluster
> -----------------------------------------
>
>                 Key: NIFI-4171
>                 URL: https://issues.apache.org/jira/browse/NIFI-4171
>             Project: Apache NiFi
>          Issue Type: Bug
>            Reporter: Shreya Bhat
>            Priority: Major
>
> Nifi service failed to start on a secure cluster after install of the service. The stderr shows :
> {code}
> Traceback (most recent call last):
>   File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 313, in <module>
>     Master().execute()
>   File "/usr/lib/python2.6/site-packages/resource_management/libraries/script/script.py", line 329, in execute
>     method(env)
>   File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 181, in start
>     self.configure(env, is_starting = True)
>   File "/usr/lib/python2.6/site-packages/resource_management/libraries/script/script.py", line 119, in locking_configure
>     original_configure(obj, *args, **kw)
>   File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 105, in configure
>     params.nifi_properties = self.setup_keystore_truststore(is_starting, params, config_version_file)
>   File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 236, in setup_keystore_truststore
>     updated_properties = self.run_toolkit_client(ca_client_dict, params.nifi_config_dir, params.jdk64_home, params.nifi_user, params.nifi_group, params.toolkit_tmp_dir, params.stack_support_toolkit_update)
>   File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 256, in run_toolkit_client
>     raise Fail("Call to tls-toolkit encountered error: {0}".format(out))
> resource_management.core.exceptions.Fail: Call to tls-toolkit encountered error: 2017/07/10 00:02:10 INFO [main] org.apache.nifi.toolkit.tls.service.client.TlsCertificateAuthorityClient: Requesting new certificate from nat-r7-taws-hdfdeploy-1.openstacklocal:10443
> 2017/07/10 00:02:11 INFO [main] org.apache.nifi.toolkit.tls.service.client.TlsCertificateSigningRequestPerformer: Requesting certificate with dn CN=nat-r7-taws-hdfdeploy-4.openstacklocal,OU=NIFI from nat-r7-taws-hdfdeploy-1.openstacklocal:10443
> Service client error: Connect to nat-r7-taws-hdfdeploy-1.openstacklocal:10443 [nat-r7-taws-hdfdeploy-1.openstacklocal/172.22.81.93] failed: Connection refused (Connection refused)
> Usage: tls-toolkit service [-h] [args]
> Services:
>    standalone: Creates certificates and config files for nifi cluster.
>    server: Acts as a Certificate Authority that can be used by clients to get Certificates
>    client: Generates a private key and gets it signed by the certificate authority.
> Traceback (most recent call last):
>   File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 313, in <module>
>     Master().execute()
>   File "/usr/lib/python2.6/site-packages/resource_management/libraries/script/script.py", line 329, in execute
>     method(env)
>   File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 181, in start
>     self.configure(env, is_starting = True)
>   File "/usr/lib/python2.6/site-packages/resource_management/libraries/script/script.py", line 119, in locking_configure
>     original_configure(obj, *args, **kw)
>   File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 105, in configure
>     params.nifi_properties = self.setup_keystore_truststore(is_starting, params, config_version_file)
>   File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 236, in setup_keystore_truststore
>     updated_properties = self.run_toolkit_client(ca_client_dict, params.nifi_config_dir, params.jdk64_home, params.nifi_user, params.nifi_group, params.toolkit_tmp_dir, params.stack_support_toolkit_update)
>   File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 256, in run_toolkit_client
>     raise Fail("Call to tls-toolkit encountered error: {0}".format(out))
> resource_management.core.exceptions.Fail: Call to tls-toolkit encountered error: 2017/07/10 00:02:18 INFO [main] org.apache.nifi.toolkit.tls.service.client.TlsCertificateAuthorityClient: Requesting new certificate from nat-r7-taws-hdfdeploy-1.openstacklocal:10443
> 2017/07/10 00:02:19 INFO [main] org.apache.nifi.toolkit.tls.service.client.TlsCertificateSigningRequestPerformer: Requesting certificate with dn CN=nat-r7-taws-hdfdeploy-4.openstacklocal,OU=NIFI from nat-r7-taws-hdfdeploy-1.openstacklocal:10443
> Service client error: Connect to nat-r7-taws-hdfdeploy-1.openstacklocal:10443 [nat-r7-taws-hdfdeploy-1.openstacklocal/172.22.81.93] failed: Connection refused (Connection refused)
> Usage: tls-toolkit service [-h] [args]
> Services:
>    standalone: Creates certificates and config files for nifi cluster.
>    server: Acts as a Certificate Authority that can be used by clients to get Certificates
>    client: Generates a private key and gets it signed by the certificate authority.
> Traceback (most recent call last):
>   File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 313, in <module>
>     Master().execute()
>   File "/usr/lib/python2.6/site-packages/resource_management/libraries/script/script.py", line 329, in execute
>     method(env)
>   File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 181, in start
>     self.configure(env, is_starting = True)
>   File "/usr/lib/python2.6/site-packages/resource_management/libraries/script/script.py", line 119, in locking_configure
>     original_configure(obj, *args, **kw)
>   File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 105, in configure
>     params.nifi_properties = self.setup_keystore_truststore(is_starting, params, config_version_file)
>   File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 236, in setup_keystore_truststore
>     updated_properties = self.run_toolkit_client(ca_client_dict, params.nifi_config_dir, params.jdk64_home, params.nifi_user, params.nifi_group, params.toolkit_tmp_dir, params.stack_support_toolkit_update)
>   File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 256, in run_toolkit_client
>     raise Fail("Call to tls-toolkit encountered error: {0}".format(out))
> resource_management.core.exceptions.Fail: Call to tls-toolkit encountered error: 2017/07/10 00:02:28 INFO [main] org.apache.nifi.toolkit.tls.service.client.TlsCertificateAuthorityClient: Requesting new certificate from nat-r7-taws-hdfdeploy-1.openstacklocal:10443
> 2017/07/10 00:02:29 INFO [main] org.apache.nifi.toolkit.tls.service.client.TlsCertificateSigningRequestPerformer: Requesting certificate with dn CN=nat-r7-taws-hdfdeploy-4.openstacklocal,OU=NIFI from nat-r7-taws-hdfdeploy-1.openstacklocal:10443
> Service client error: Connect to nat-r7-taws-hdfdeploy-1.openstacklocal:10443 [nat-r7-taws-hdfdeploy-1.openstacklocal/172.22.81.93] failed: Connection refused (Connection refused)
> Usage: tls-toolkit service [-h] [args]
> Services:
>    standalone: Creates certificates and config files for nifi cluster.
>    server: Acts as a Certificate Authority that can be used by clients to get Certificates
>    client: Generates a private key and gets it signed by the certificate authority.
> Traceback (most recent call last):
>   File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 313, in <module>
>     Master().execute()
>   File "/usr/lib/python2.6/site-packages/resource_management/libraries/script/script.py", line 329, in execute
>     method(env)
>   File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 181, in start
>     self.configure(env, is_starting = True)
>   File "/usr/lib/python2.6/site-packages/resource_management/libraries/script/script.py", line 119, in locking_configure
>     original_configure(obj, *args, **kw)
>   File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 105, in configure
>     params.nifi_properties = self.setup_keystore_truststore(is_starting, params, config_version_file)
>   File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 236, in setup_keystore_truststore
>     updated_properties = self.run_toolkit_client(ca_client_dict, params.nifi_config_dir, params.jdk64_home, params.nifi_user, params.nifi_group, params.toolkit_tmp_dir, params.stack_support_toolkit_update)
>   File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 256, in run_toolkit_client
>     raise Fail("Call to tls-toolkit encountered error: {0}".format(out))
> resource_management.core.exceptions.Fail: Call to tls-toolkit encountered error: 2017/07/10 00:02:46 INFO [main] org.apache.nifi.toolkit.tls.service.client.TlsCertificateAuthorityClient: Requesting new certificate from nat-r7-taws-hdfdeploy-1.openstacklocal:10443
> 2017/07/10 00:02:47 INFO [main] org.apache.nifi.toolkit.tls.service.client.TlsCertificateSigningRequestPerformer: Requesting certificate with dn CN=nat-r7-taws-hdfdeploy-4.openstacklocal,OU=NIFI from nat-r7-taws-hdfdeploy-1.openstacklocal:10443
> Service client error: Connect to nat-r7-taws-hdfdeploy-1.openstacklocal:10443 [nat-r7-taws-hdfdeploy-1.openstacklocal/172.22.81.93] failed: Connection refused (Connection refused)
> Usage: tls-toolkit service [-h] [args]
> Services:
>    standalone: Creates certificates and config files for nifi cluster.
>    server: Acts as a Certificate Authority that can be used by clients to get Certificates
>    client: Generates a private key and gets it signed by the certificate authority.
> Traceback (most recent call last):
>   File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 313, in <module>
>     Master().execute()
>   File "/usr/lib/python2.6/site-packages/resource_management/libraries/script/script.py", line 329, in execute
>     method(env)
>   File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 181, in start
>     self.configure(env, is_starting = True)
>   File "/usr/lib/python2.6/site-packages/resource_management/libraries/script/script.py", line 119, in locking_configure
>     original_configure(obj, *args, **kw)
>   File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 105, in configure
>     params.nifi_properties = self.setup_keystore_truststore(is_starting, params, config_version_file)
>   File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 236, in setup_keystore_truststore
>     updated_properties = self.run_toolkit_client(ca_client_dict, params.nifi_config_dir, params.jdk64_home, params.nifi_user, params.nifi_group, params.toolkit_tmp_dir, params.stack_support_toolkit_update)
>   File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 256, in run_toolkit_client
>     raise Fail("Call to tls-toolkit encountered error: {0}".format(out))
> resource_management.core.exceptions.Fail: Call to tls-toolkit encountered error: 2017/07/10 00:03:08 INFO [main] org.apache.nifi.toolkit.tls.service.client.TlsCertificateAuthorityClient: Requesting new certificate from nat-r7-taws-hdfdeploy-1.openstacklocal:10443
> 2017/07/10 00:03:09 INFO [main] org.apache.nifi.toolkit.tls.service.client.TlsCertificateSigningRequestPerformer: Requesting certificate with dn CN=nat-r7-taws-hdfdeploy-4.openstacklocal,OU=NIFI from nat-r7-taws-hdfdeploy-1.openstacklocal:10443
> Service client error: Connect to nat-r7-taws-hdfdeploy-1.openstacklocal:10443 [nat-r7-taws-hdfdeploy-1.openstacklocal/172.22.81.93] failed: Connection refused (Connection refused)
> Usage: tls-toolkit service [-h] [args]
> Services:
>    standalone: Creates certificates and config files for nifi cluster.
>    server: Acts as a Certificate Authority that can be used by clients to get Certificates
>    client: Generates a private key and gets it signed by the certificate authority.
> Traceback (most recent call last):
>   File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 313, in <module>
>     Master().execute()
>   File "/usr/lib/python2.6/site-packages/resource_management/libraries/script/script.py", line 329, in execute
>     method(env)
>   File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 181, in start
>     self.configure(env, is_starting = True)
>   File "/usr/lib/python2.6/site-packages/resource_management/libraries/script/script.py", line 119, in locking_configure
>     original_configure(obj, *args, **kw)
>   File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 105, in configure
>     params.nifi_properties = self.setup_keystore_truststore(is_starting, params, config_version_file)
>   File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 236, in setup_keystore_truststore
>     updated_properties = self.run_toolkit_client(ca_client_dict, params.nifi_config_dir, params.jdk64_home, params.nifi_user, params.nifi_group, params.toolkit_tmp_dir, params.stack_support_toolkit_update)
>   File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 256, in run_toolkit_client
>     raise Fail("Call to tls-toolkit encountered error: {0}".format(out))
> resource_management.core.exceptions.Fail: Call to tls-toolkit encountered error: 2017/07/10 00:03:47 INFO [main] org.apache.nifi.toolkit.tls.service.client.TlsCertificateAuthorityClient: Requesting new certificate from nat-r7-taws-hdfdeploy-1.openstacklocal:10443
> 2017/07/10 00:03:48 INFO [main] org.apache.nifi.toolkit.tls.service.client.TlsCertificateSigningRequestPerformer: Requesting certificate with dn CN=nat-r7-taws-hdfdeploy-4.openstacklocal,OU=NIFI from nat-r7-taws-hdfdeploy-1.openstacklocal:10443
> Service client error: Connect to nat-r7-taws-hdfdeploy-1.openstacklocal:10443 [nat-r7-taws-hdfdeploy-1.openstacklocal/172.22.81.93] failed: Connection refused (Connection refused)
> Usage: tls-toolkit service [-h] [args]
> Services:
>    standalone: Creates certificates and config files for nifi cluster.
>    server: Acts as a Certificate Authority that can be used by clients to get Certificates
>    client: Generates a private key and gets it signed by the certificate authority.
> Traceback (most recent call last):
>   File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 313, in <module>
>     Master().execute()
>   File "/usr/lib/python2.6/site-packages/resource_management/libraries/script/script.py", line 329, in execute
>     method(env)
>   File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 181, in start
>     self.configure(env, is_starting = True)
>   File "/usr/lib/python2.6/site-packages/resource_management/libraries/script/script.py", line 119, in locking_configure
>     original_configure(obj, *args, **kw)
>   File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 105, in configure
>     params.nifi_properties = self.setup_keystore_truststore(is_starting, params, config_version_file)
>   File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 236, in setup_keystore_truststore
>     updated_properties = self.run_toolkit_client(ca_client_dict, params.nifi_config_dir, params.jdk64_home, params.nifi_user, params.nifi_group, params.toolkit_tmp_dir, params.stack_support_toolkit_update)
>   File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 256, in run_toolkit_client
>     raise Fail("Call to tls-toolkit encountered error: {0}".format(out))
> resource_management.core.exceptions.Fail: Call to tls-toolkit encountered error: 2017/07/10 00:04:57 INFO [main] org.apache.nifi.toolkit.tls.service.client.TlsCertificateAuthorityClient: Requesting new certificate from nat-r7-taws-hdfdeploy-1.openstacklocal:10443
> 2017/07/10 00:04:59 INFO [main] org.apache.nifi.toolkit.tls.service.client.TlsCertificateSigningRequestPerformer: Requesting certificate with dn CN=nat-r7-taws-hdfdeploy-4.openstacklocal,OU=NIFI from nat-r7-taws-hdfdeploy-1.openstacklocal:10443
> Service client error: Connect to nat-r7-taws-hdfdeploy-1.openstacklocal:10443 [nat-r7-taws-hdfdeploy-1.openstacklocal/172.22.81.93] failed: Connection refused (Connection refused)
> Usage: tls-toolkit service [-h] [args]
> Services:
>    standalone: Creates certificates and config files for nifi cluster.
>    server: Acts as a Certificate Authority that can be used by clients to get Certificates
>    client: Generates a private key and gets it signed by the certificate authority.
> Traceback (most recent call last):
>   File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 313, in <module>
>     Master().execute()
>   File "/usr/lib/python2.6/site-packages/resource_management/libraries/script/script.py", line 329, in execute
>     method(env)
>   File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 181, in start
>     self.configure(env, is_starting = True)
>   File "/usr/lib/python2.6/site-packages/resource_management/libraries/script/script.py", line 119, in locking_configure
>     original_configure(obj, *args, **kw)
>   File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 105, in configure
>     params.nifi_properties = self.setup_keystore_truststore(is_starting, params, config_version_file)
>   File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 236, in setup_keystore_truststore
>     updated_properties = self.run_toolkit_client(ca_client_dict, params.nifi_config_dir, params.jdk64_home, params.nifi_user, params.nifi_group, params.toolkit_tmp_dir, params.stack_support_toolkit_update)
>   File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 256, in run_toolkit_client
>     raise Fail("Call to tls-toolkit encountered error: {0}".format(out))
> resource_management.core.exceptions.Fail: Call to tls-toolkit encountered error: 2017/07/10 00:07:13 INFO [main] org.apache.nifi.toolkit.tls.service.client.TlsCertificateAuthorityClient: Requesting new certificate from nat-r7-taws-hdfdeploy-1.openstacklocal:10443
> 2017/07/10 00:07:15 INFO [main] org.apache.nifi.toolkit.tls.service.client.TlsCertificateSigningRequestPerformer: Requesting certificate with dn CN=nat-r7-taws-hdfdeploy-4.openstacklocal,OU=NIFI from nat-r7-taws-hdfdeploy-1.openstacklocal:10443
> Service client error: Connect to nat-r7-taws-hdfdeploy-1.openstacklocal:10443 [nat-r7-taws-hdfdeploy-1.openstacklocal/172.22.81.93] failed: Connection refused (Connection refused)
> Usage: tls-toolkit service [-h] [args]
> Services:
>    standalone: Creates certificates and config files for nifi cluster.
>    server: Acts as a Certificate Authority that can be used by clients to get Certificates
>    client: Generates a private key and gets it signed by the certificate authority.
> Traceback (most recent call last):
>   File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 313, in <module>
>     Master().execute()
>   File "/usr/lib/python2.6/site-packages/resource_management/libraries/script/script.py", line 329, in execute
>     method(env)
>   File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 181, in start
>     self.configure(env, is_starting = True)
>   File "/usr/lib/python2.6/site-packages/resource_management/libraries/script/script.py", line 119, in locking_configure
>     original_configure(obj, *args, **kw)
>   File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 105, in configure
>     params.nifi_properties = self.setup_keystore_truststore(is_starting, params, config_version_file)
>   File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 236, in setup_keystore_truststore
>     updated_properties = self.run_toolkit_client(ca_client_dict, params.nifi_config_dir, params.jdk64_home, params.nifi_user, params.nifi_group, params.toolkit_tmp_dir, params.stack_support_toolkit_update)
>   File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 256, in run_toolkit_client
>     raise Fail("Call to tls-toolkit encountered error: {0}".format(out))
> resource_management.core.exceptions.Fail: Call to tls-toolkit encountered error: 2017/07/10 00:11:37 INFO [main] org.apache.nifi.toolkit.tls.service.client.TlsCertificateAuthorityClient: Requesting new certificate from nat-r7-taws-hdfdeploy-1.openstacklocal:10443
> 2017/07/10 00:11:38 INFO [main] org.apache.nifi.toolkit.tls.service.client.TlsCertificateSigningRequestPerformer: Requesting certificate with dn CN=nat-r7-taws-hdfdeploy-4.openstacklocal,OU=NIFI from nat-r7-taws-hdfdeploy-1.openstacklocal:10443
> Service client error: Connect to nat-r7-taws-hdfdeploy-1.openstacklocal:10443 [nat-r7-taws-hdfdeploy-1.openstacklocal/172.22.81.93] failed: Connection refused (Connection refused)
> Usage: tls-toolkit service [-h] [args]
> Services:
>    standalone: Creates certificates and config files for nifi cluster.
>    server: Acts as a Certificate Authority that can be used by clients to get Certificates
>    client: Generates a private key and gets it signed by the certificate authority.
> Traceback (most recent call last):
>   File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 313, in <module>
>     Master().execute()
>   File "/usr/lib/python2.6/site-packages/resource_management/libraries/script/script.py", line 329, in execute
>     method(env)
>   File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 181, in start
>     self.configure(env, is_starting = True)
>   File "/usr/lib/python2.6/site-packages/resource_management/libraries/script/script.py", line 119, in locking_configure
>     original_configure(obj, *args, **kw)
>   File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 105, in configure
>     params.nifi_properties = self.setup_keystore_truststore(is_starting, params, config_version_file)
>   File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 236, in setup_keystore_truststore
>     updated_properties = self.run_toolkit_client(ca_client_dict, params.nifi_config_dir, params.jdk64_home, params.nifi_user, params.nifi_group, params.toolkit_tmp_dir, params.stack_support_toolkit_update)
>   File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 256, in run_toolkit_client
>     raise Fail("Call to tls-toolkit encountered error: {0}".format(out))
> resource_management.core.exceptions.Fail: Call to tls-toolkit encountered error: 2017/07/10 00:20:27 INFO [main] org.apache.nifi.toolkit.tls.service.client.TlsCertificateAuthorityClient: Requesting new certificate from nat-r7-taws-hdfdeploy-1.openstacklocal:10443
> 2017/07/10 00:20:28 INFO [main] org.apache.nifi.toolkit.tls.service.client.TlsCertificateSigningRequestPerformer: Requesting certificate with dn CN=nat-r7-taws-hdfdeploy-4.openstacklocal,OU=NIFI from nat-r7-taws-hdfdeploy-1.openstacklocal:10443
> Service client error: Connect to nat-r7-taws-hdfdeploy-1.openstacklocal:10443 [nat-r7-taws-hdfdeploy-1.openstacklocal/172.22.81.93] failed: Connection refused (Connection refused)
> Usage: tls-toolkit service [-h] [args]
> Services:
>    standalone: Creates certificates and config files for nifi cluster.
>    server: Acts as a Certificate Authority that can be used by clients to get Certificates
>    client: Generates a private key and gets it signed by the certificate authority.
> Traceback (most recent call last):
>   File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 313, in <module>
>     Master().execute()
>   File "/usr/lib/python2.6/site-packages/resource_management/libraries/script/script.py", line 329, in execute
>     method(env)
>   File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 181, in start
>     self.configure(env, is_starting = True)
>   File "/usr/lib/python2.6/site-packages/resource_management/libraries/script/script.py", line 119, in locking_configure
>     original_configure(obj, *args, **kw)
>   File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 105, in configure
>     params.nifi_properties = self.setup_keystore_truststore(is_starting, params, config_version_file)
>   File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 236, in setup_keystore_truststore
>     updated_properties = self.run_toolkit_client(ca_client_dict, params.nifi_config_dir, params.jdk64_home, params.nifi_user, params.nifi_group, params.toolkit_tmp_dir, params.stack_support_toolkit_update)
>   File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 256, in run_toolkit_client
>     raise Fail("Call to tls-toolkit encountered error: {0}".format(out))
> resource_management.core.exceptions.Fail: Call to tls-toolkit encountered error: 2017/07/10 00:22:13 INFO [main] org.apache.nifi.toolkit.tls.service.client.TlsCertificateAuthorityClient: Requesting new certificate from nat-r7-taws-hdfdeploy-1.openstacklocal:10443
> 2017/07/10 00:22:14 INFO [main] org.apache.nifi.toolkit.tls.service.client.TlsCertificateSigningRequestPerformer: Requesting certificate with dn CN=nat-r7-taws-hdfdeploy-4.openstacklocal,OU=NIFI from nat-r7-taws-hdfdeploy-1.openstacklocal:10443
> Service client error: Connect to nat-r7-taws-hdfdeploy-1.openstacklocal:10443 [nat-r7-taws-hdfdeploy-1.openstacklocal/172.22.81.93] failed: Connection refused (Connection refused)
> Usage: tls-toolkit service [-h] [args]
> Services:
>    standalone: Creates certificates and config files for nifi cluster.
>    server: Acts as a Certificate Authority that can be used by clients to get Certificates
>    client: Generates a private key and gets it signed by the certificate authority.
> {code}



--
This message was sent by Atlassian Jira
(v8.3.4#803005)