Installing Key Trustee KMS
Also, when the Key Trustee KMS role is created, it is tightly bound to the identity of the host on which it is installed. Moving the role to a different host, changing the host name, or changing the IP of the host is not supported.
Key Trustee KMS is a custom Key Management Server (KMS) that uses Cloudera Navigator Key Trustee Server as the underlying keystore, instead of the file-based Java KeyStore (JKS) used by the default Hadoop KMS.
The KMS (Navigator Key Trustee) service in Cloudera Manager 5.3 is renamed to Key Trustee KMS in Cloudera Manager 5.4.
Setting Up an Internal Repository
You must create an internal repository to install Key Trustee KMS. For instructions on creating internal repositories (including Cloudera Manager, CDH, and Cloudera Navigator encryption components), see Creating and Using a Parcel Repository for Cloudera Manager if you are using parcels, or Creating and Using a Package Repository for Cloudera Manager if you are using packages.
Installing Key Trustee KMS Using Parcels
- Go to .
- Click Configuration and add your internal repository to the Remote Parcel Repository URLs section. See Configuring the Cloudera Manager Server to Use the Parcel URL for Hosted Repositories for more information.
- Download, distribute, and activate the Key Trustee KMS parcel. See Managing Parcels for detailed instructions
on using parcels to install or upgrade components.
Note: The KEYTRUSTEE_SERVER parcel in Cloudera Manager is not the Key Trustee KMS parcel; it is the Key Trustee Server parcel. The parcel name for Key Trustee KMS is KEYTRUSTEE.
Installing Key Trustee KMS Using Packages
- After Setting Up an Internal Repository, configure the Key Trustee KMS host to use the repository. See Modifying Clients to Find the Repository for more information.
- Because the keytrustee-keyprovider package depends on the hadoop-kms package, you must add the CDH repository. See To add the CDH repository for instructions. If you want to create an internal CDH repository, see Creating a Local Yum Repository.
- Install the keytrustee-keyprovider package using the appropriate command for your operating system:
- RHEL-compatible
$ sudo yum install keytrustee-keyprovider
- SLES
$ sudo zypper install keytrustee-keyprovider
- Ubuntu or Debian
$ sudo apt-get install keytrustee-keyprovider
- RHEL-compatible
Post-Installation Configuration
<< Installing Cloudera Navigator Key HSM | ©2016 Cloudera, Inc. All rights reserved | Installing Navigator HSM KMS Backed by Thales HSM >> |
Terms and Conditions Privacy Policy |