Enabling and Renewing SSL for Self-signed Certificates

Enable and renew SSL for self-signed certificates using Ambari (requires 3.4.0 or later). A self-signed certificate is created, signed, and issued by the subject of the certificate.

Note

Enable/Renew SSL are the same in Big Data Service ODH, and if certificates are expired, the entire set of certificates must be regenerated using the regular SSL enablement process. We recommend creating a notification based on the certificate expiration time. For more information, see Creating an Alarm.
  1. Access Apache Ambari with administrator user and password.
  2. In the Ambari UI, navigate to Views, then SSL Management View.
  3. Select Configure Services.
    Configure Services in Ambari UI.
  4. Under Configurable Services, find the service that you want to enable SSL for.
  5. Switch the service from Disabled to Enabled.
  6. Select Save Configuration.
  7. (Optional) To view or update SSL-related configuration properties, select Advanced Configurations.
    Advanced Configurations in Ambari UI.
  8. (Optional) To import an LDAP certificate, or to test connectivity, select LDAP Configurations.
    LDAP Configurations in Ambari UI.