Ambari-Agent无法连接Ambari-Server(SSL协议错误)求助
Problem Description
After installing Ambari Server via a local httpd repo and confirming hosts through the WebUI, the following SSL error occurs repeatedly:
INFO 2018-05-27 15:39:16,776 NetUtil.py:70 - Connecting to https://master:8440/ca ERROR 2018-05-27 15:39:16,787 NetUtil.py:96 - [Errno 8] _ssl.c:493: EOF occurred in violation of protocol ERROR 2018-05-27 15:39:16,788 NetUtil.py:97 - SSLError: Failed to connect.Please check openssl library versions. Refer to: https://bugzilla.redhat.com/show_bug.cgi?id=1022468 for more details. WARNING 2018-05-27 15:39:16,789 NetUtil.py:124 - Server at https://master:8440 is not reachable, sleeping for 10 seconds... INFO 2018-05-27 15:39:26,793 NetUtil.py:70 - Connecting to https://master:8440/ca ERROR 2018-05-27 15:39:26,799 NetUtil.py:96 - [Errno 8] _ssl.c:493: EOF occurred in violation of protocol ERROR 2018-05-27 15:39:26,799 NetUtil.py:97 - SSLError: Failed to connect. Please check openssl library versions.Refer to: https://bugzilla.redhat.com/show_bug.cgi?id=1022468 for more details. WARNING 2018-05-27 15:39:26,801 NetUtil.py:124 - Server at https://master:8440 is not reachable, sleeping for 10 seconds...
Environment details:
- CentOS Linux release 7.5.1804 (Core)
- Python 2.7.5
- Java 1.8.0_171
- OpenSSL 1.0.2k
- Ambari 2.6.2.0
- HDP-2.6.5.0
Note: All Ambari Agent nodes can successfully telnet to master:8440:
[root@slave2 ~]# telnet master 8440 Trying 192.168.17.128... Connected to master. Escape character is '^]'.
Solution
I ran into this exact SSL protocol compatibility issue when deploying Ambari 2.6.x on CentOS 7.5. Here are targeted fixes that worked for me:
1. Force Ambari Server to use TLSv1.2
Edit the Ambari Server configuration file:
vi /etc/ambari-server/conf/ambari.properties
Add or modify these parameters to enforce TLSv1.2 and compatible cipher suites:
ambari.server.ssl.protocol=TLSv1.2 ambari.server.ssl.cipher.suite=ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-DSS-AES128-GCM-SHA256:kEDH+AESGCM:ECDHE-RSA-AES128-SHA256:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA:ECDHE-ECDSA-AES256-SHA:DHE-RSA-AES128-SHA256:DHE-RSA-AES128-SHA:DHE-DSS-AES128-SHA256:DHE-RSA-AES256-SHA256:DHE-DSS-AES256-SHA:DHE-RSA-AES256-SHA:AES128-GCM-SHA256:AES256-GCM-SHA384:AES128-SHA256:AES256-SHA256:AES128-SHA:AES256-SHA:AES:CAMELLIA:DES-CBC3-SHA:!aNULL:!eNULL:!EXPORT:!DES:!RC4:!MD5:!PSK:!aECDH:!EDH-DSS-DES-CBC3-SHA:!EDH-RSA-DES-CBC3-SHA:!KRB5-DES-CBC3-SHA
Restart Ambari Server to apply changes:
ambari-server restart
2. Fix Python SSL Module Compatibility
CentOS 7's default Python 2.7.5 sometimes has limited TLSv1.2 support. First test if Python can connect using TLSv1.2:
python -c "import socket, ssl; conn = ssl.wrap_socket(socket.socket(), ssl_version=ssl.PROTOCOL_TLSv1_2); conn.connect(('master', 8440)); print('Connection successful')"
If this fails, install pyOpenSSL to enhance Python's SSL capabilities:
yum install pyOpenSSL -y
3. Update Ambari Agent SSL Settings
On every Agent node, edit the agent configuration:
vi /etc/ambari-agent/conf/ambari-agent.ini
Under the [security] section, add:
ssl_protocol = TLSv1.2
Restart the Ambari Agent:
ambari-agent restart
4. Verify System-Wide Crypto Policies
Ensure CentOS's crypto policy allows TLSv1.2:
update-crypto-policies --set DEFAULT
This sets the system to use default secure protocols, including TLSv1.2. Reboot the server if needed to apply fully.
Why This Happens
CentOS 7.5 has stricter default SSL policies that may conflict with Ambari 2.6.2's default SSL configuration. Even though telnet confirms the port is open, the SSL handshake fails because of incompatible protocol versions (Ambari might be trying to use older SSL protocols that the system blocks). Forcing TLSv1.2 aligns both sides and resolves the EOF error.
内容的提问来源于stack exchange,提问作者kaful Mo

