Support Questions
Find answers, ask questions, and share your expertise
Announcements
Alert: Welcome to the Unified Cloudera Community. Former HCC members be sure to read and learn how to activate your account here.

Is it possible to roll over selected DEK in ranger ? If not, do DEKs expire or can we set a default expiry on DEKs upon their generation?

Is it possible to roll over selected DEK in ranger ? If not, do DEKs expire or can we set a default expiry on DEKs upon their generation?

New Contributor
 
2 REPLIES 2
Highlighted

Re: Is it possible to roll over selected DEK in ranger ? If not, do DEKs expire or can we set a default expiry on DEKs upon their generation?

Guru

Hello @bharat uniyal,

Yes, it is possible to roll over a single DEK. You can use KMS REST API to do this. (Source - search for 'Rollover Key'). Once a key is rolled over, all the subsequent operation will use the new key.

As for DEK expiry, unfortunately Hadoop KMS does not support expiry of the keys. So you can not set expiry on the keys.

Hope this helps !

Highlighted

Re: Is it possible to roll over selected DEK in ranger ? If not, do DEKs expire or can we set a default expiry on DEKs upon their generation?

New Contributor

Thanks Vipin,

I should have been more specific.

I know that we can rollover an ecryption zone key(EZK) but, I also wanted to understand if there is a way to expire or rollover a file level DEK if in case I want to change or remove compromised file level DEKs.

Don't have an account?
Coming from Hortonworks? Activate your account here