<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Impala client configuration documentation out of sync with CM in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Impala-client-configuration-documentation-out-of-sync-with/m-p/54424#M60524</link>
    <description>&lt;P&gt;&lt;A href="https://www.cloudera.com/documentation/enterprise/5-9-x/topics/impala_ssl.html" target="_blank"&gt;https://www.cloudera.com/documentation/enterprise/5-9-x/topics/impala_ssl.html&lt;/A&gt; shows a bunch of "TLS/SSL ... Client" properties that no longer appear in CM for CDH 5.9.0. Is there an update to the documentation available that covers this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have Impala running behind a proxy and I am also wondering about how this fits in.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;While I am here, HiveServer2 documentation indicates Kerberos and LDAP client authentication can co-exist but CM doesn't allow for this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Clearly the documentation around client authentication could be better. Any pointers to updates would be appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks, S.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 16 Sep 2022 11:33:52 GMT</pubDate>
    <dc:creator>ScottE</dc:creator>
    <dc:date>2022-09-16T11:33:52Z</dc:date>
    <item>
      <title>Impala client configuration documentation out of sync with CM</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Impala-client-configuration-documentation-out-of-sync-with/m-p/54424#M60524</link>
      <description>&lt;P&gt;&lt;A href="https://www.cloudera.com/documentation/enterprise/5-9-x/topics/impala_ssl.html" target="_blank"&gt;https://www.cloudera.com/documentation/enterprise/5-9-x/topics/impala_ssl.html&lt;/A&gt; shows a bunch of "TLS/SSL ... Client" properties that no longer appear in CM for CDH 5.9.0. Is there an update to the documentation available that covers this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have Impala running behind a proxy and I am also wondering about how this fits in.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;While I am here, HiveServer2 documentation indicates Kerberos and LDAP client authentication can co-exist but CM doesn't allow for this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Clearly the documentation around client authentication could be better. Any pointers to updates would be appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks, S.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Sep 2022 11:33:52 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Impala-client-configuration-documentation-out-of-sync-with/m-p/54424#M60524</guid>
      <dc:creator>ScottE</dc:creator>
      <dc:date>2022-09-16T11:33:52Z</dc:date>
    </item>
    <item>
      <title>Re: Impala client configuration documentation out of sync with CM</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Impala-client-configuration-documentation-out-of-sync-with/m-p/55115#M60525</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/12678"&gt;@ScottE&lt;/a&gt; wrote:&lt;BR /&gt;&lt;P&gt;&lt;A href="https://www.cloudera.com/documentation/enterprise/5-9-x/topics/impala_ssl.html" target="_blank"&gt;https://www.cloudera.com/documentation/enterprise/5-9-x/topics/impala_ssl.html&lt;/A&gt; shows a bunch of "TLS/SSL ... Client" properties that no longer appear in CM for CDH 5.9.0. Is there an update to the documentation available that covers this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have Impala running behind a proxy and I am also wondering about how this fits in.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;While I am here, HiveServer2 documentation indicates Kerberos and LDAP client authentication can co-exist but CM doesn't allow for this.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;For the above three items:&lt;/P&gt;&lt;P&gt;The "TLS/SSL ... Client" properties are now just prefixed simply "&lt;SPAN&gt;Impala TLS/SSL Server&lt;/SPAN&gt;" - this should be a documentation change.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If Impala is behind a proxy you need to configure HAProxy with a TLS certificate and have it connect to the Impala Server instances also using TLS. The HAProxy documentation will help, but some additional documentaiton from Cloudera would be nice.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HiveServer2 does not support simultaineous kerberos and LDAP authentication (the way Impala does). To achieve this for Hive you need to run a second HiveServer2 instance, configuring one with kerbeos authentication and the other with LDAP.&lt;/P&gt;</description>
      <pubDate>Fri, 26 May 2017 13:26:11 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Impala-client-configuration-documentation-out-of-sync-with/m-p/55115#M60525</guid>
      <dc:creator>ScottE</dc:creator>
      <dc:date>2017-05-26T13:26:11Z</dc:date>
    </item>
  </channel>
</rss>

