<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Key Trustee KMS Proxy ACLs confusion in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Key-Trustee-KMS-Proxy-ACLs-confusion/m-p/59459#M67458</link>
    <description>&lt;P&gt;&lt;SPAN&gt;The username and/or group should be a user present in Linux and Kerberos that you have designated as the user responsible for managing keys on your cluster, and you can use an existing user/group or create a new one as makes sense in your environment. Typically this would be a group of administrators who you would entrust to configure security for you, so that only one user or a handful of users can grant access.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 31 Aug 2017 06:16:09 GMT</pubDate>
    <dc:creator>Nae2Ju7w</dc:creator>
    <dc:date>2017-08-31T06:16:09Z</dc:date>
    <item>
      <title>Key Trustee KMS Proxy ACLs confusion</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Key-Trustee-KMS-Proxy-ACLs-confusion/m-p/59450#M67457</link>
      <description>&lt;P&gt;In the&amp;nbsp;&lt;A href="https://www.cloudera.com/documentation/enterprise/5-11-x/PDF/cloudera-security.pdf" target="_blank"&gt;Cloudera Security Guide&lt;/A&gt;, step 6 on page 303 for adding a Key Trusteee KMS Service says "&lt;SPAN&gt;To generate the recommended ACLS, enter the username and group responsible for managing cryptographic keys and click &lt;/SPAN&gt;&lt;SPAN&gt;Generate ACLs&lt;/SPAN&gt;&lt;SPAN&gt;."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Are&amp;nbsp;the username and group mentioned in this step arbitrary or is it referencing a username and group that should have been created as part of some previous configuration?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Aug 2017 18:31:35 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Key-Trustee-KMS-Proxy-ACLs-confusion/m-p/59450#M67457</guid>
      <dc:creator>Nae2Ju7w</dc:creator>
      <dc:date>2017-08-30T18:31:35Z</dc:date>
    </item>
    <item>
      <title>Re: Key Trustee KMS Proxy ACLs confusion</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Key-Trustee-KMS-Proxy-ACLs-confusion/m-p/59459#M67458</link>
      <description>&lt;P&gt;&lt;SPAN&gt;The username and/or group should be a user present in Linux and Kerberos that you have designated as the user responsible for managing keys on your cluster, and you can use an existing user/group or create a new one as makes sense in your environment. Typically this would be a group of administrators who you would entrust to configure security for you, so that only one user or a handful of users can grant access.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Aug 2017 06:16:09 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Key-Trustee-KMS-Proxy-ACLs-confusion/m-p/59459#M67458</guid>
      <dc:creator>Nae2Ju7w</dc:creator>
      <dc:date>2017-08-31T06:16:09Z</dc:date>
    </item>
  </channel>
</rss>

