Hive Metastore启用TLS配置及SSL握手失败问题求助
Hive Metastore TLS 启用配置与握手失败问题排查
一、核心配置说明
不需要基于Thrift URL创建新的XML配置文件,所有TLS相关配置均可在metastore-site.xml中完成,conf-site.xml为Hadoop通用配置文件,Hive Metastore的TLS配置核心依赖前者。
二、关键配置项检查
先确认你在metastore-site.xml中是否配置了以下必填项:
hive.metastore.ssl.enabled:设为true,开启SSL功能hive.metastore.ssl.keystore.path:密钥库文件的绝对路径(注意:Java应用仅识别JKS/PKCS12格式,PEM格式证书需转换后使用)hive.metastore.ssl.keystore.password:密钥库密码hive.metastore.ssl.truststore.path:信任库文件绝对路径(单向认证可与密钥库复用)hive.metastore.ssl.truststore.password:信任库密码- 若启用双向TLS(要求客户端提供证书),需添加
hive.metastore.ssl.client.auth并设为required或optional
三、openssl握手失败原因分析
从你的命令输出看:
[root@primmer1 lh-hms-poc]# openssl s_client -connect 9.30.94.163:9083 -cert cert.crt -key cert.key CONNECTED(00000003) 139828257847184:error:140790E5:SSL routines:ssl23_write:ssl handshake failure:s23_lib.c:177: --- no peer certificate available --- No client certificate CA names sent --- SSL handshake has read 0 bytes and written 289 bytes --- New, (NONE), Cipher is (NONE) Secure Renegotiation IS NOT supported Compression: NONE Expansion: NONE No ALPN negotiated SSL-Session: Protocol : TLSv1.2 Cipher : 0000 Session-ID: Session-ID-ctx: Master-Key: Key-Arg : None Krb5 Principal: None PSK identity: None PSK identity hint: None Start Time: 1672830872 Timeout : 300 (sec) Verify return code: 0 (ok) ---
核心问题是Hive Metastore服务端未返回证书,说明服务端TLS配置未生效,可能原因:
- 修改配置后未重启Hive Metastore服务,或服务未加载到正确的配置文件
- 密钥库格式错误:你生成的
cert.crt和cert.key是PEM格式,无法被Java直接识别,需转换为JKS/PKCS12 - 端口配置不匹配:9083是默认非SSL Thrift端口,若启用SSL需确认服务端是否在该端口开启了SSL监听,或配置
hive.metastore.port指定SSL端口
四、正确配置与验证步骤
1. 转换证书格式
将PEM证书和密钥转为PKCS12格式(Java支持):
openssl pkcs12 -export -in cert.crt -inkey cert.key -out metastore.p12 -name metastore
可选转为JKS格式:
keytool -importkeystore -srckeystore metastore.p12 -srcstoretype PKCS12 -destkeystore metastore.jks -deststoretype JKS
2. 完善metastore-site.xml配置
添加以下配置片段:
<property> <name>hive.metastore.ssl.enabled</name> <value>true</value> </property> <property> <name>hive.metastore.ssl.keystore.path</name> <value>/绝对路径/metastore.jks</value> </property> <property> <name>hive.metastore.ssl.keystore.password</name> <value>你的密钥库密码</value> </property> <property> <name>hive.metastore.ssl.truststore.path</name> <value>/绝对路径/metastore.jks</value> </property> <property> <name>hive.metastore.ssl.truststore.password</name> <value>你的信任库密码</value> </property> <!-- 双向认证需添加 --> <property> <name>hive.metastore.ssl.client.auth</name> <value>required</value> </property>
3. 重启服务并验证
- 重启Hive Metastore服务,查看启动日志,确认无SSL初始化或密钥库读取错误
- 使用openssl验证(双向认证场景):
openssl s_client -connect 9.30.94.163:9083 -cert cert.crt -key cert.key -CAfile ca.crt
单向认证场景无需-cert和-key参数:
openssl s_client -connect 9.30.94.163:9083 -CAfile ca.crt
- 也可通过Hive客户端验证:在客户端
hive-site.xml添加相同信任库配置,执行show databases测试连接
五、常见排查点
- 检查Hive Metastore启动日志,确认是否有
SSL initialization failed或密钥库权限错误 - 确保Hive运行用户对密钥库文件有读取权限
- 若使用CDH、HDP等发行版,优先通过集群管理界面配置SSL,避免直接修改XML文件导致配置不生效
内容的提问来源于stack exchange,提问作者Arsha Aruni
相关产品推荐
相关产品推荐

