<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Do we need Cloudera Navigator to Install KMS and KTS? in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/Do-we-need-Cloudera-Navigator-to-Install-KMS-and-KTS/m-p/301165#M220535</link>
    <description>&lt;P&gt;Hi &lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/31607"&gt;@paras&lt;/a&gt; , do I need to install this first? how can I know if I have already installed key trustee server?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2020-08-10 at 9.38.15 AM.png" style="width: 940px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/28547i4724BF2203DBF741/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2020-08-10 at 9.38.15 AM.png" alt="Screen Shot 2020-08-10 at 9.38.15 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 10 Aug 2020 01:40:05 GMT</pubDate>
    <dc:creator>Mondi</dc:creator>
    <dc:date>2020-08-10T01:40:05Z</dc:date>
    <item>
      <title>Do we need Cloudera Navigator to Install KMS and KTS?</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Do-we-need-Cloudera-Navigator-to-Install-KMS-and-KTS/m-p/301042#M220495</link>
      <description>&lt;P&gt;We are planning to install KMS and KTS but do we need Cloudera Navigator to Install KMS and KTS? if not required, then how to install it without Cloudera Navigator?&lt;/P&gt;</description>
      <pubDate>Fri, 07 Aug 2020 02:17:31 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Do-we-need-Cloudera-Navigator-to-Install-KMS-and-KTS/m-p/301042#M220495</guid>
      <dc:creator>Mondi</dc:creator>
      <dc:date>2020-08-07T02:17:31Z</dc:date>
    </item>
    <item>
      <title>Re: Do we need Cloudera Navigator to Install KMS and KTS?</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Do-we-need-Cloudera-Navigator-to-Install-KMS-and-KTS/m-p/301056#M220503</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/75200"&gt;@Mondi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You do not need to install Cloudera Navigator for KMS and KTS.&lt;/P&gt;&lt;P&gt;Refer :&amp;nbsp;&lt;A href="https://docs.cloudera.com/documentation/enterprise/6/6.3/topics/encryption_prereqs.html#concept_g23_454_y5__section_n4w_b5v_ls" target="_blank" rel="noopener"&gt;https://docs.cloudera.com/documentation/enterprise/6/6.3/topics/encryption_prereqs.html#concept_g23_454_y5__section_n4w_b5v_ls&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please refer below documents for encrypting data at rest requirement and installing KMS and KTS.&amp;nbsp;&lt;SPAN&gt;You must install Key Trustee Server before installing and using Key Trustee KMS.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.cloudera.com/documentation/enterprise/6/6.3/topics/encryption_planning.html#concept_c4m_knq_w5" target="_blank" rel="noopener"&gt;https://docs.cloudera.com/documentation/enterprise/6/6.3/topics/encryption_planning.html#concept_c4m_knq_w5&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.cloudera.com/documentation/enterprise/6/6.3/topics/key_trustee_install.html#xd_583c10bfdbd326ba-590cb1d1-149e9ca9886--7b84" target="_blank" rel="noopener"&gt;https://docs.cloudera.com/documentation/enterprise/6/6.3/topics/key_trustee_install.html#xd_583c10bfdbd326ba-590cb1d1-149e9ca9886--7b84&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.cloudera.com/documentation/enterprise/6/6.3/topics/cm_ig_install_keytrustee.html#xd_583c10bfdbd326ba-590cb1d1-149e9ca9886--7860" target="_blank" rel="noopener"&gt;https://docs.cloudera.com/documentation/enterprise/6/6.3/topics/cm_ig_install_keytrustee.html#xd_583c10bfdbd326ba-590cb1d1-149e9ca9886--7860&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Hope this helps,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Paras&lt;/SPAN&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;I&gt;Was your question answered? Make sure to mark the answer as the accepted solution.&lt;/I&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;I&gt;If you find a reply useful, say thanks by clicking on the thumbs up button.&lt;/I&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Aug 2020 08:09:48 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Do-we-need-Cloudera-Navigator-to-Install-KMS-and-KTS/m-p/301056#M220503</guid>
      <dc:creator>paras</dc:creator>
      <dc:date>2020-08-07T08:09:48Z</dc:date>
    </item>
    <item>
      <title>Re: Do we need Cloudera Navigator to Install KMS and KTS?</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Do-we-need-Cloudera-Navigator-to-Install-KMS-and-KTS/m-p/301165#M220535</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/31607"&gt;@paras&lt;/a&gt; , do I need to install this first? how can I know if I have already installed key trustee server?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2020-08-10 at 9.38.15 AM.png" style="width: 940px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/28547i4724BF2203DBF741/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2020-08-10 at 9.38.15 AM.png" alt="Screen Shot 2020-08-10 at 9.38.15 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Aug 2020 01:40:05 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Do-we-need-Cloudera-Navigator-to-Install-KMS-and-KTS/m-p/301165#M220535</guid>
      <dc:creator>Mondi</dc:creator>
      <dc:date>2020-08-10T01:40:05Z</dc:date>
    </item>
    <item>
      <title>Re: Do we need Cloudera Navigator to Install KMS and KTS?</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Do-we-need-Cloudera-Navigator-to-Install-KMS-and-KTS/m-p/301195#M220556</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/75200"&gt;@Mondi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Cloudera provides two implementations of the Hadoop KMS. Refer below document for more details.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs.cloudera.com/documentation/enterprise/latest/topics/cdh_sg_kms.html" target="_blank" rel="noopener"&gt;https://docs.cloudera.com/documentation/enterprise/latest/topics/cdh_sg_kms.html&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;You need to install&amp;nbsp;Key Trustee KMS only when using KTS as backing keystore&amp;nbsp;instead of the file-based Java KeyStore (JKS) used by the default Hadoop KMS.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;There should be a separate cluster for keytrustee server. This would be mentioned as one of the steps when you enable HDFS encryption via the wizard.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Refer below document&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs.cloudera.com/documentation/enterprise/6/6.3/topics/sg_hdfs_encryption_wizard.html#concept_n2p_5vq_vt" target="_blank" rel="noopener"&gt;https://docs.cloudera.com/documentation/enterprise/6/6.3/topics/sg_hdfs_encryption_wizard.html#concept_n2p_5vq_vt&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Hope this helps,&lt;BR /&gt;Paras&lt;BR /&gt;&lt;STRONG&gt;&lt;I&gt;Was your question answered? Make sure to mark the answer as the accepted solution.&lt;/I&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;I&gt;If you find a reply useful, say thanks by clicking on the thumbs up button.&lt;/I&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Aug 2020 13:25:38 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Do-we-need-Cloudera-Navigator-to-Install-KMS-and-KTS/m-p/301195#M220556</guid>
      <dc:creator>paras</dc:creator>
      <dc:date>2020-08-10T13:25:38Z</dc:date>
    </item>
    <item>
      <title>Re: Do we need Cloudera Navigator to Install KMS and KTS?</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Do-we-need-Cloudera-Navigator-to-Install-KMS-and-KTS/m-p/301259#M220570</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/31607"&gt;@paras&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks for replying. if my understanding is correct, you mean that my KMS or KTS server must be in a different cluster? the server must no be registered on the same cluster?&lt;BR /&gt;&lt;BR /&gt;Also do we need SSL for the KMS? we are planning to install the default Hadoop KMS Java Keystore KMS.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Aug 2020 10:28:11 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Do-we-need-Cloudera-Navigator-to-Install-KMS-and-KTS/m-p/301259#M220570</guid>
      <dc:creator>Mondi</dc:creator>
      <dc:date>2020-08-11T10:28:11Z</dc:date>
    </item>
    <item>
      <title>Re: Do we need Cloudera Navigator to Install KMS and KTS?</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Do-we-need-Cloudera-Navigator-to-Install-KMS-and-KTS/m-p/301270#M220578</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/75200"&gt;@Mondi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;KMS service should be installed on your CDH cluster. Before installing KMS, you should have a dedicated cluster added using the Cloudera manager Add Cluster option which has the KTS service roles installed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you are installing&amp;nbsp;&lt;SPAN&gt;default Hadoop KMS Java Keystore KMS, the above can be ignored since the default Hadoop KMS included in CDH uses a file-based Java KeyStore (JKS) for its backing keystore. You can simply add the service from Cloudera Manager.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class="body conbody"&gt;&lt;DIV class="section"&gt;&lt;P class="p"&gt;Cloudera strongly recommends that you enable TLS for both the HDFS and the Key Trustee KMS services to prevent the passage of plain text key material between the KMS and HDFS data nodes.&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Refer below document&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://docs.cloudera.com/documentation/enterprise/latest/topics/sg_hdfs_encryption_wizard.html#concept_fcq_phr_wt" target="_blank" rel="noopener"&gt;https://docs.cloudera.com/documentation/enterprise/latest/topics/sg_hdfs_encryption_wizard.html#concept_fcq_phr_wt&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Hope this helps,&lt;BR /&gt;Paras&lt;BR /&gt;&lt;STRONG&gt;&lt;I&gt;Was your question answered? Make sure to mark the answer as the accepted solution.&lt;/I&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;I&gt;If you find a reply useful, say thanks by clicking on the thumbs up button.&lt;/I&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Aug 2020 13:53:16 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Do-we-need-Cloudera-Navigator-to-Install-KMS-and-KTS/m-p/301270#M220578</guid>
      <dc:creator>paras</dc:creator>
      <dc:date>2020-08-11T13:53:16Z</dc:date>
    </item>
    <item>
      <title>Re: Do we need Cloudera Navigator to Install KMS and KTS?</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Do-we-need-Cloudera-Navigator-to-Install-KMS-and-KTS/m-p/301309#M220605</link>
      <description>&lt;P&gt;Thanks for your answer. &lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/31607"&gt;@paras&lt;/a&gt; one more thing, Java Keystore KMS requires SSL? can I do encryption without an SSL using Java Keystore KMS?&lt;/P&gt;</description>
      <pubDate>Wed, 12 Aug 2020 01:56:40 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Do-we-need-Cloudera-Navigator-to-Install-KMS-and-KTS/m-p/301309#M220605</guid>
      <dc:creator>Mondi</dc:creator>
      <dc:date>2020-08-12T01:56:40Z</dc:date>
    </item>
    <item>
      <title>Re: Do we need Cloudera Navigator to Install KMS and KTS?</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Do-we-need-Cloudera-Navigator-to-Install-KMS-and-KTS/m-p/301367#M220629</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/75200"&gt;@Mondi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is not compulsory to enable SSL but recommended&amp;nbsp;&lt;SPAN&gt;to prevent the passage of plain text key material between the KMS and HDFS data nodes.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;You can continue to install&amp;nbsp;&lt;SPAN&gt;Java Keystore KMS&amp;nbsp;without adding SSL configurations.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Hope this helps,&lt;BR /&gt;Paras&lt;BR /&gt;&lt;STRONG&gt;&lt;I&gt;Was your question answered? Make sure to mark the answer as the accepted solution.&lt;/I&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;I&gt;If you find a reply useful, say thanks by clicking on the thumbs up button.&lt;/I&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Aug 2020 15:24:54 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Do-we-need-Cloudera-Navigator-to-Install-KMS-and-KTS/m-p/301367#M220629</guid>
      <dc:creator>paras</dc:creator>
      <dc:date>2020-08-12T15:24:54Z</dc:date>
    </item>
  </channel>
</rss>

