Support Questions
Find answers, ask questions, and share your expertise
Announcements
Alert: Welcome to the Unified Cloudera Community. Former HCC members be sure to read and learn how to activate your account here.

Enabling HDFS encryption

Highlighted

Enabling HDFS encryption

New Contributor

Hi,

 

I'm seting up HDFS Data At Rest Encryption via Cloudera Manager. All necessary steps are done (kerberized, TLS/SSL level 3, added Java KeyStore KMS, validate encryption etc). All steps completed, no error in log files.  And I'm stuck and cannot proceed further. What I'm missing?

 

The screen is:

2017-12-27_115225.png

 

Version: CDH 5.13.1, Parcels 

4 REPLIES 4
Highlighted

Re: Enabling HDFS encryption

Expert Contributor

Hello Janusz,

 

Please verify if your entropy requirement in-place. You can do so by following steps mentioned in this link Entropy Requirements

 

Hope that gives you further clarity.

Highlighted

Re: Enabling HDFS encryption

New Contributor

I am having the same issue setting up HDFS Data AT Rest Encryption via Cloudera Manager (Cloudera Express v5.7.0 in a docker container).   My screen is identical to the one shown above and I am stuck on that page.  I have checked entropy using the `cat /proc/sys/kernel/random/entropy_avail` command and it is consistently returning values greater than 3700.  The Java Keystore KMS was started through the Cluster menu option and is listening on port 16000.  I have not added TLS/SSL.  Is that the issue or is there something else that I'm missing?

Highlighted

Re: Enabling HDFS encryption

New Contributor

Re: Enabling HDFS encryption

New Contributor

Thank you for your response.  These were the steps I was following.  The problem was that at the ACLs step, I didn't know what to put in and so I clicked away from that step and the wizard took that as an entry and wouldn't let me edit it again.  I had to stop that docker container and start over again.  The next time, I put "cloudera,kms,root" in that field and then I was able to continue through the process and successfully restart the stale service and redeploy the client configuration.  For new users who have never used Cloudera before, the documentation isn't really clear and some examples would really be helpful!

Don't have an account?
Coming from Hortonworks? Activate your account here