You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Ambari-Agent无法连接Ambari-Server(SSL协议错误)求助

Ambari Server SSL Connection Failure (EOF in Violation of Protocol)

Problem Description

After installing Ambari Server via a local httpd repo and confirming hosts through the WebUI, the following SSL error occurs repeatedly:

INFO 2018-05-27 15:39:16,776 NetUtil.py:70 - Connecting to https://master:8440/ca
ERROR 2018-05-27 15:39:16,787 NetUtil.py:96 - [Errno 8] _ssl.c:493: EOF occurred in violation of protocol
ERROR 2018-05-27 15:39:16,788 NetUtil.py:97 - SSLError: Failed to connect.Please check openssl library versions. Refer to: https://bugzilla.redhat.com/show_bug.cgi?id=1022468 for more details.
WARNING 2018-05-27 15:39:16,789 NetUtil.py:124 - Server at https://master:8440 is not reachable, sleeping for 10 seconds...
INFO 2018-05-27 15:39:26,793 NetUtil.py:70 - Connecting to https://master:8440/ca
ERROR 2018-05-27 15:39:26,799 NetUtil.py:96 - [Errno 8] _ssl.c:493: EOF occurred in violation of protocol
ERROR 2018-05-27 15:39:26,799 NetUtil.py:97 - SSLError: Failed to connect. Please check openssl library versions.Refer to: https://bugzilla.redhat.com/show_bug.cgi?id=1022468 for more details.
WARNING 2018-05-27 15:39:26,801 NetUtil.py:124 - Server at https://master:8440 is not reachable, sleeping for 10 seconds...

Environment details:

  • CentOS Linux release 7.5.1804 (Core)
  • Python 2.7.5
  • Java 1.8.0_171
  • OpenSSL 1.0.2k
  • Ambari 2.6.2.0
  • HDP-2.6.5.0

Note: All Ambari Agent nodes can successfully telnet to master:8440:

[root@slave2 ~]# telnet master 8440
Trying 192.168.17.128...
Connected to master.
Escape character is '^]'.

Solution

I ran into this exact SSL protocol compatibility issue when deploying Ambari 2.6.x on CentOS 7.5. Here are targeted fixes that worked for me:

1. Force Ambari Server to use TLSv1.2

Edit the Ambari Server configuration file:

vi /etc/ambari-server/conf/ambari.properties

Add or modify these parameters to enforce TLSv1.2 and compatible cipher suites:

ambari.server.ssl.protocol=TLSv1.2
ambari.server.ssl.cipher.suite=ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-DSS-AES128-GCM-SHA256:kEDH+AESGCM:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA:ECDHE-ECDSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-DSS-AES128-SHA256:DHE-RSA-AES256-SHA256:DHE-DSS-AES256-SHA:DHE-RSA-AES256-SHA:AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-SHA256:AES256-SHA256:AES128-SHA:AES256-SHA:AES:CAMELLIA:DES-CBC3-SHA:!aNULL:!eNULL:!EXPORT:!DES:!RC4:!MD5:!PSK:!aECDH:!EDH-DSS-DES-CBC3-SHA:!EDH-RSA-DES-CBC3-SHA:!KRB5-DES-CBC3-SHA

Restart Ambari Server to apply changes:

ambari-server restart

2. Fix Python SSL Module Compatibility

CentOS 7's default Python 2.7.5 sometimes has limited TLSv1.2 support. First test if Python can connect using TLSv1.2:

python -c "import socket, ssl; conn = ssl.wrap_socket(socket.socket(), ssl_version=ssl.PROTOCOL_TLSv1_2); conn.connect(('master', 8440)); print('Connection successful')"

If this fails, install pyOpenSSL to enhance Python's SSL capabilities:

yum install pyOpenSSL -y

3. Update Ambari Agent SSL Settings

On every Agent node, edit the agent configuration:

vi /etc/ambari-agent/conf/ambari-agent.ini

Under the [security] section, add:

ssl_protocol = TLSv1.2

Restart the Ambari Agent:

ambari-agent restart

4. Verify System-Wide Crypto Policies

Ensure CentOS's crypto policy allows TLSv1.2:

update-crypto-policies --set DEFAULT

This sets the system to use default secure protocols, including TLSv1.2. Reboot the server if needed to apply fully.


Why This Happens

CentOS 7.5 has stricter default SSL policies that may conflict with Ambari 2.6.2's default SSL configuration. Even though telnet confirms the port is open, the SSL handshake fails because of incompatible protocol versions (Ambari might be trying to use older SSL protocols that the system blocks). Forcing TLSv1.2 aligns both sides and resolves the EOF error.

内容的提问来源于stack exchange,提问作者kaful Mo

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.29 07:46:11