This section describes how to configure the for integration with KMS system for Cloudera. It assumes that access to the cluster is gated by Sentry.
Before you begin, please verify the pre-requisites. See Configure for KMS.
In the following sections:
Enable HDFS EncryptionOn the Cloudera cluster, you may enable HDFS encryption using a designated Java KeyStore. For more information, see http://www.cloudera.com/documentation/enterprise/latest/topics/sg_hdfs_encryption_wizard.html?scroll=concept_n2p_5vq_vt#concept_fcq_phr_wt_unique_1. Java KMS ConfigurationAdditional configuration for the Java KMS is required. See http://www.cloudera.com/documentation/enterprise/latest/topics/cdh_sg_kms.html. Java KeyStore KMS ConfigurationIn the
In Cloudera Manager, you may wish to change the following safety value value. Navigate to KMS service > Configuration > Advanced > Key Management Server Proxy Advanced Configuration Snippet (Safety Valve) for kms-site.xml. Modify the following:
In the
HDFS ConfigurationIn
Save the files. |
After the configuration is complete, you can try to import a dataset from a source stored in a cluster location managed by KMS, assuming that any required authentication configuration has been completed. See Import Data Page.
For more information, see Configure Hadoop Authentication.