Shreya Bhat created NIFI-4171: --------------------------------- Summary: NIFI service wont start on secure cluster Key: NIFI-4171 URL: https://issues.apache.org/jira/browse/NIFI-4171 Project: Apache NiFi Issue Type: Bug Reporter: Shreya Bhat
Nifi service failed to start on a secure cluster after install of the service. The stderr shows : {code} Traceback (most recent call last): File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 313, in <module> Master().execute() File "/usr/lib/python2.6/site-packages/resource_management/libraries/script/script.py", line 329, in execute method(env) File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 181, in start self.configure(env, is_starting = True) File "/usr/lib/python2.6/site-packages/resource_management/libraries/script/script.py", line 119, in locking_configure original_configure(obj, *args, **kw) File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 105, in configure params.nifi_properties = self.setup_keystore_truststore(is_starting, params, config_version_file) File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 236, in setup_keystore_truststore updated_properties = self.run_toolkit_client(ca_client_dict, params.nifi_config_dir, params.jdk64_home, params.nifi_user, params.nifi_group, params.toolkit_tmp_dir, params.stack_support_toolkit_update) File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 256, in run_toolkit_client raise Fail("Call to tls-toolkit encountered error: {0}".format(out)) resource_management.core.exceptions.Fail: Call to tls-toolkit encountered error: 2017/07/10 00:02:10 INFO [main] org.apache.nifi.toolkit.tls.service.client.TlsCertificateAuthorityClient: Requesting new certificate from nat-r7-taws-hdfdeploy-1.openstacklocal:10443 2017/07/10 00:02:11 INFO [main] org.apache.nifi.toolkit.tls.service.client.TlsCertificateSigningRequestPerformer: Requesting certificate with dn CN=nat-r7-taws-hdfdeploy-4.openstacklocal,OU=NIFI from nat-r7-taws-hdfdeploy-1.openstacklocal:10443 Service client error: Connect to nat-r7-taws-hdfdeploy-1.openstacklocal:10443 [nat-r7-taws-hdfdeploy-1.openstacklocal/172.22.81.93] failed: Connection refused (Connection refused) Usage: tls-toolkit service [-h] [args] Services: standalone: Creates certificates and config files for nifi cluster. server: Acts as a Certificate Authority that can be used by clients to get Certificates client: Generates a private key and gets it signed by the certificate authority. Traceback (most recent call last): File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 313, in <module> Master().execute() File "/usr/lib/python2.6/site-packages/resource_management/libraries/script/script.py", line 329, in execute method(env) File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 181, in start self.configure(env, is_starting = True) File "/usr/lib/python2.6/site-packages/resource_management/libraries/script/script.py", line 119, in locking_configure original_configure(obj, *args, **kw) File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 105, in configure params.nifi_properties = self.setup_keystore_truststore(is_starting, params, config_version_file) File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 236, in setup_keystore_truststore updated_properties = self.run_toolkit_client(ca_client_dict, params.nifi_config_dir, params.jdk64_home, params.nifi_user, params.nifi_group, params.toolkit_tmp_dir, params.stack_support_toolkit_update) File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 256, in run_toolkit_client raise Fail("Call to tls-toolkit encountered error: {0}".format(out)) resource_management.core.exceptions.Fail: Call to tls-toolkit encountered error: 2017/07/10 00:02:18 INFO [main] org.apache.nifi.toolkit.tls.service.client.TlsCertificateAuthorityClient: Requesting new certificate from nat-r7-taws-hdfdeploy-1.openstacklocal:10443 2017/07/10 00:02:19 INFO [main] org.apache.nifi.toolkit.tls.service.client.TlsCertificateSigningRequestPerformer: Requesting certificate with dn CN=nat-r7-taws-hdfdeploy-4.openstacklocal,OU=NIFI from nat-r7-taws-hdfdeploy-1.openstacklocal:10443 Service client error: Connect to nat-r7-taws-hdfdeploy-1.openstacklocal:10443 [nat-r7-taws-hdfdeploy-1.openstacklocal/172.22.81.93] failed: Connection refused (Connection refused) Usage: tls-toolkit service [-h] [args] Services: standalone: Creates certificates and config files for nifi cluster. server: Acts as a Certificate Authority that can be used by clients to get Certificates client: Generates a private key and gets it signed by the certificate authority. Traceback (most recent call last): File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 313, in <module> Master().execute() File "/usr/lib/python2.6/site-packages/resource_management/libraries/script/script.py", line 329, in execute method(env) File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 181, in start self.configure(env, is_starting = True) File "/usr/lib/python2.6/site-packages/resource_management/libraries/script/script.py", line 119, in locking_configure original_configure(obj, *args, **kw) File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 105, in configure params.nifi_properties = self.setup_keystore_truststore(is_starting, params, config_version_file) File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 236, in setup_keystore_truststore updated_properties = self.run_toolkit_client(ca_client_dict, params.nifi_config_dir, params.jdk64_home, params.nifi_user, params.nifi_group, params.toolkit_tmp_dir, params.stack_support_toolkit_update) File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 256, in run_toolkit_client raise Fail("Call to tls-toolkit encountered error: {0}".format(out)) resource_management.core.exceptions.Fail: Call to tls-toolkit encountered error: 2017/07/10 00:02:28 INFO [main] org.apache.nifi.toolkit.tls.service.client.TlsCertificateAuthorityClient: Requesting new certificate from nat-r7-taws-hdfdeploy-1.openstacklocal:10443 2017/07/10 00:02:29 INFO [main] org.apache.nifi.toolkit.tls.service.client.TlsCertificateSigningRequestPerformer: Requesting certificate with dn CN=nat-r7-taws-hdfdeploy-4.openstacklocal,OU=NIFI from nat-r7-taws-hdfdeploy-1.openstacklocal:10443 Service client error: Connect to nat-r7-taws-hdfdeploy-1.openstacklocal:10443 [nat-r7-taws-hdfdeploy-1.openstacklocal/172.22.81.93] failed: Connection refused (Connection refused) Usage: tls-toolkit service [-h] [args] Services: standalone: Creates certificates and config files for nifi cluster. server: Acts as a Certificate Authority that can be used by clients to get Certificates client: Generates a private key and gets it signed by the certificate authority. Traceback (most recent call last): File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 313, in <module> Master().execute() File "/usr/lib/python2.6/site-packages/resource_management/libraries/script/script.py", line 329, in execute method(env) File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 181, in start self.configure(env, is_starting = True) File "/usr/lib/python2.6/site-packages/resource_management/libraries/script/script.py", line 119, in locking_configure original_configure(obj, *args, **kw) File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 105, in configure params.nifi_properties = self.setup_keystore_truststore(is_starting, params, config_version_file) File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 236, in setup_keystore_truststore updated_properties = self.run_toolkit_client(ca_client_dict, params.nifi_config_dir, params.jdk64_home, params.nifi_user, params.nifi_group, params.toolkit_tmp_dir, params.stack_support_toolkit_update) File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 256, in run_toolkit_client raise Fail("Call to tls-toolkit encountered error: {0}".format(out)) resource_management.core.exceptions.Fail: Call to tls-toolkit encountered error: 2017/07/10 00:02:46 INFO [main] org.apache.nifi.toolkit.tls.service.client.TlsCertificateAuthorityClient: Requesting new certificate from nat-r7-taws-hdfdeploy-1.openstacklocal:10443 2017/07/10 00:02:47 INFO [main] org.apache.nifi.toolkit.tls.service.client.TlsCertificateSigningRequestPerformer: Requesting certificate with dn CN=nat-r7-taws-hdfdeploy-4.openstacklocal,OU=NIFI from nat-r7-taws-hdfdeploy-1.openstacklocal:10443 Service client error: Connect to nat-r7-taws-hdfdeploy-1.openstacklocal:10443 [nat-r7-taws-hdfdeploy-1.openstacklocal/172.22.81.93] failed: Connection refused (Connection refused) Usage: tls-toolkit service [-h] [args] Services: standalone: Creates certificates and config files for nifi cluster. server: Acts as a Certificate Authority that can be used by clients to get Certificates client: Generates a private key and gets it signed by the certificate authority. Traceback (most recent call last): File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 313, in <module> Master().execute() File "/usr/lib/python2.6/site-packages/resource_management/libraries/script/script.py", line 329, in execute method(env) File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 181, in start self.configure(env, is_starting = True) File "/usr/lib/python2.6/site-packages/resource_management/libraries/script/script.py", line 119, in locking_configure original_configure(obj, *args, **kw) File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 105, in configure params.nifi_properties = self.setup_keystore_truststore(is_starting, params, config_version_file) File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 236, in setup_keystore_truststore updated_properties = self.run_toolkit_client(ca_client_dict, params.nifi_config_dir, params.jdk64_home, params.nifi_user, params.nifi_group, params.toolkit_tmp_dir, params.stack_support_toolkit_update) File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 256, in run_toolkit_client raise Fail("Call to tls-toolkit encountered error: {0}".format(out)) resource_management.core.exceptions.Fail: Call to tls-toolkit encountered error: 2017/07/10 00:03:08 INFO [main] org.apache.nifi.toolkit.tls.service.client.TlsCertificateAuthorityClient: Requesting new certificate from nat-r7-taws-hdfdeploy-1.openstacklocal:10443 2017/07/10 00:03:09 INFO [main] org.apache.nifi.toolkit.tls.service.client.TlsCertificateSigningRequestPerformer: Requesting certificate with dn CN=nat-r7-taws-hdfdeploy-4.openstacklocal,OU=NIFI from nat-r7-taws-hdfdeploy-1.openstacklocal:10443 Service client error: Connect to nat-r7-taws-hdfdeploy-1.openstacklocal:10443 [nat-r7-taws-hdfdeploy-1.openstacklocal/172.22.81.93] failed: Connection refused (Connection refused) Usage: tls-toolkit service [-h] [args] Services: standalone: Creates certificates and config files for nifi cluster. server: Acts as a Certificate Authority that can be used by clients to get Certificates client: Generates a private key and gets it signed by the certificate authority. Traceback (most recent call last): File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 313, in <module> Master().execute() File "/usr/lib/python2.6/site-packages/resource_management/libraries/script/script.py", line 329, in execute method(env) File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 181, in start self.configure(env, is_starting = True) File "/usr/lib/python2.6/site-packages/resource_management/libraries/script/script.py", line 119, in locking_configure original_configure(obj, *args, **kw) File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 105, in configure params.nifi_properties = self.setup_keystore_truststore(is_starting, params, config_version_file) File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 236, in setup_keystore_truststore updated_properties = self.run_toolkit_client(ca_client_dict, params.nifi_config_dir, params.jdk64_home, params.nifi_user, params.nifi_group, params.toolkit_tmp_dir, params.stack_support_toolkit_update) File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 256, in run_toolkit_client raise Fail("Call to tls-toolkit encountered error: {0}".format(out)) resource_management.core.exceptions.Fail: Call to tls-toolkit encountered error: 2017/07/10 00:03:47 INFO [main] org.apache.nifi.toolkit.tls.service.client.TlsCertificateAuthorityClient: Requesting new certificate from nat-r7-taws-hdfdeploy-1.openstacklocal:10443 2017/07/10 00:03:48 INFO [main] org.apache.nifi.toolkit.tls.service.client.TlsCertificateSigningRequestPerformer: Requesting certificate with dn CN=nat-r7-taws-hdfdeploy-4.openstacklocal,OU=NIFI from nat-r7-taws-hdfdeploy-1.openstacklocal:10443 Service client error: Connect to nat-r7-taws-hdfdeploy-1.openstacklocal:10443 [nat-r7-taws-hdfdeploy-1.openstacklocal/172.22.81.93] failed: Connection refused (Connection refused) Usage: tls-toolkit service [-h] [args] Services: standalone: Creates certificates and config files for nifi cluster. server: Acts as a Certificate Authority that can be used by clients to get Certificates client: Generates a private key and gets it signed by the certificate authority. Traceback (most recent call last): File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 313, in <module> Master().execute() File "/usr/lib/python2.6/site-packages/resource_management/libraries/script/script.py", line 329, in execute method(env) File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 181, in start self.configure(env, is_starting = True) File "/usr/lib/python2.6/site-packages/resource_management/libraries/script/script.py", line 119, in locking_configure original_configure(obj, *args, **kw) File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 105, in configure params.nifi_properties = self.setup_keystore_truststore(is_starting, params, config_version_file) File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 236, in setup_keystore_truststore updated_properties = self.run_toolkit_client(ca_client_dict, params.nifi_config_dir, params.jdk64_home, params.nifi_user, params.nifi_group, params.toolkit_tmp_dir, params.stack_support_toolkit_update) File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 256, in run_toolkit_client raise Fail("Call to tls-toolkit encountered error: {0}".format(out)) resource_management.core.exceptions.Fail: Call to tls-toolkit encountered error: 2017/07/10 00:04:57 INFO [main] org.apache.nifi.toolkit.tls.service.client.TlsCertificateAuthorityClient: Requesting new certificate from nat-r7-taws-hdfdeploy-1.openstacklocal:10443 2017/07/10 00:04:59 INFO [main] org.apache.nifi.toolkit.tls.service.client.TlsCertificateSigningRequestPerformer: Requesting certificate with dn CN=nat-r7-taws-hdfdeploy-4.openstacklocal,OU=NIFI from nat-r7-taws-hdfdeploy-1.openstacklocal:10443 Service client error: Connect to nat-r7-taws-hdfdeploy-1.openstacklocal:10443 [nat-r7-taws-hdfdeploy-1.openstacklocal/172.22.81.93] failed: Connection refused (Connection refused) Usage: tls-toolkit service [-h] [args] Services: standalone: Creates certificates and config files for nifi cluster. server: Acts as a Certificate Authority that can be used by clients to get Certificates client: Generates a private key and gets it signed by the certificate authority. Traceback (most recent call last): File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 313, in <module> Master().execute() File "/usr/lib/python2.6/site-packages/resource_management/libraries/script/script.py", line 329, in execute method(env) File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 181, in start self.configure(env, is_starting = True) File "/usr/lib/python2.6/site-packages/resource_management/libraries/script/script.py", line 119, in locking_configure original_configure(obj, *args, **kw) File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 105, in configure params.nifi_properties = self.setup_keystore_truststore(is_starting, params, config_version_file) File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 236, in setup_keystore_truststore updated_properties = self.run_toolkit_client(ca_client_dict, params.nifi_config_dir, params.jdk64_home, params.nifi_user, params.nifi_group, params.toolkit_tmp_dir, params.stack_support_toolkit_update) File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 256, in run_toolkit_client raise Fail("Call to tls-toolkit encountered error: {0}".format(out)) resource_management.core.exceptions.Fail: Call to tls-toolkit encountered error: 2017/07/10 00:07:13 INFO [main] org.apache.nifi.toolkit.tls.service.client.TlsCertificateAuthorityClient: Requesting new certificate from nat-r7-taws-hdfdeploy-1.openstacklocal:10443 2017/07/10 00:07:15 INFO [main] org.apache.nifi.toolkit.tls.service.client.TlsCertificateSigningRequestPerformer: Requesting certificate with dn CN=nat-r7-taws-hdfdeploy-4.openstacklocal,OU=NIFI from nat-r7-taws-hdfdeploy-1.openstacklocal:10443 Service client error: Connect to nat-r7-taws-hdfdeploy-1.openstacklocal:10443 [nat-r7-taws-hdfdeploy-1.openstacklocal/172.22.81.93] failed: Connection refused (Connection refused) Usage: tls-toolkit service [-h] [args] Services: standalone: Creates certificates and config files for nifi cluster. server: Acts as a Certificate Authority that can be used by clients to get Certificates client: Generates a private key and gets it signed by the certificate authority. Traceback (most recent call last): File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 313, in <module> Master().execute() File "/usr/lib/python2.6/site-packages/resource_management/libraries/script/script.py", line 329, in execute method(env) File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 181, in start self.configure(env, is_starting = True) File "/usr/lib/python2.6/site-packages/resource_management/libraries/script/script.py", line 119, in locking_configure original_configure(obj, *args, **kw) File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 105, in configure params.nifi_properties = self.setup_keystore_truststore(is_starting, params, config_version_file) File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 236, in setup_keystore_truststore updated_properties = self.run_toolkit_client(ca_client_dict, params.nifi_config_dir, params.jdk64_home, params.nifi_user, params.nifi_group, params.toolkit_tmp_dir, params.stack_support_toolkit_update) File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 256, in run_toolkit_client raise Fail("Call to tls-toolkit encountered error: {0}".format(out)) resource_management.core.exceptions.Fail: Call to tls-toolkit encountered error: 2017/07/10 00:11:37 INFO [main] org.apache.nifi.toolkit.tls.service.client.TlsCertificateAuthorityClient: Requesting new certificate from nat-r7-taws-hdfdeploy-1.openstacklocal:10443 2017/07/10 00:11:38 INFO [main] org.apache.nifi.toolkit.tls.service.client.TlsCertificateSigningRequestPerformer: Requesting certificate with dn CN=nat-r7-taws-hdfdeploy-4.openstacklocal,OU=NIFI from nat-r7-taws-hdfdeploy-1.openstacklocal:10443 Service client error: Connect to nat-r7-taws-hdfdeploy-1.openstacklocal:10443 [nat-r7-taws-hdfdeploy-1.openstacklocal/172.22.81.93] failed: Connection refused (Connection refused) Usage: tls-toolkit service [-h] [args] Services: standalone: Creates certificates and config files for nifi cluster. server: Acts as a Certificate Authority that can be used by clients to get Certificates client: Generates a private key and gets it signed by the certificate authority. Traceback (most recent call last): File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 313, in <module> Master().execute() File "/usr/lib/python2.6/site-packages/resource_management/libraries/script/script.py", line 329, in execute method(env) File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 181, in start self.configure(env, is_starting = True) File "/usr/lib/python2.6/site-packages/resource_management/libraries/script/script.py", line 119, in locking_configure original_configure(obj, *args, **kw) File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 105, in configure params.nifi_properties = self.setup_keystore_truststore(is_starting, params, config_version_file) File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 236, in setup_keystore_truststore updated_properties = self.run_toolkit_client(ca_client_dict, params.nifi_config_dir, params.jdk64_home, params.nifi_user, params.nifi_group, params.toolkit_tmp_dir, params.stack_support_toolkit_update) File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 256, in run_toolkit_client raise Fail("Call to tls-toolkit encountered error: {0}".format(out)) resource_management.core.exceptions.Fail: Call to tls-toolkit encountered error: 2017/07/10 00:20:27 INFO [main] org.apache.nifi.toolkit.tls.service.client.TlsCertificateAuthorityClient: Requesting new certificate from nat-r7-taws-hdfdeploy-1.openstacklocal:10443 2017/07/10 00:20:28 INFO [main] org.apache.nifi.toolkit.tls.service.client.TlsCertificateSigningRequestPerformer: Requesting certificate with dn CN=nat-r7-taws-hdfdeploy-4.openstacklocal,OU=NIFI from nat-r7-taws-hdfdeploy-1.openstacklocal:10443 Service client error: Connect to nat-r7-taws-hdfdeploy-1.openstacklocal:10443 [nat-r7-taws-hdfdeploy-1.openstacklocal/172.22.81.93] failed: Connection refused (Connection refused) Usage: tls-toolkit service [-h] [args] Services: standalone: Creates certificates and config files for nifi cluster. server: Acts as a Certificate Authority that can be used by clients to get Certificates client: Generates a private key and gets it signed by the certificate authority. Traceback (most recent call last): File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 313, in <module> Master().execute() File "/usr/lib/python2.6/site-packages/resource_management/libraries/script/script.py", line 329, in execute method(env) File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 181, in start self.configure(env, is_starting = True) File "/usr/lib/python2.6/site-packages/resource_management/libraries/script/script.py", line 119, in locking_configure original_configure(obj, *args, **kw) File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 105, in configure params.nifi_properties = self.setup_keystore_truststore(is_starting, params, config_version_file) File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 236, in setup_keystore_truststore updated_properties = self.run_toolkit_client(ca_client_dict, params.nifi_config_dir, params.jdk64_home, params.nifi_user, params.nifi_group, params.toolkit_tmp_dir, params.stack_support_toolkit_update) File "/var/lib/ambari-agent/cache/common-services/NIFI/1.0.0/package/scripts/nifi.py", line 256, in run_toolkit_client raise Fail("Call to tls-toolkit encountered error: {0}".format(out)) resource_management.core.exceptions.Fail: Call to tls-toolkit encountered error: 2017/07/10 00:22:13 INFO [main] org.apache.nifi.toolkit.tls.service.client.TlsCertificateAuthorityClient: Requesting new certificate from nat-r7-taws-hdfdeploy-1.openstacklocal:10443 2017/07/10 00:22:14 INFO [main] org.apache.nifi.toolkit.tls.service.client.TlsCertificateSigningRequestPerformer: Requesting certificate with dn CN=nat-r7-taws-hdfdeploy-4.openstacklocal,OU=NIFI from nat-r7-taws-hdfdeploy-1.openstacklocal:10443 Service client error: Connect to nat-r7-taws-hdfdeploy-1.openstacklocal:10443 [nat-r7-taws-hdfdeploy-1.openstacklocal/172.22.81.93] failed: Connection refused (Connection refused) Usage: tls-toolkit service [-h] [args] Services: standalone: Creates certificates and config files for nifi cluster. server: Acts as a Certificate Authority that can be used by clients to get Certificates client: Generates a private key and gets it signed by the certificate authority. {code} -- This message was sent by Atlassian JIRA (v6.4.14#64029)