Encrypting Data at Rest in Cloudera Manager
Encrypting Data at Rest
Data at Rest Encryption Reference Architecture
Data at Rest Encryption Requirements
Resource Planning for Data at Rest Encryption
HDFS Transparent Encryption
Key Concepts and Architecture
Keystores and the Key Management Server
Data Encryption Components and Solutions
Encryption Zones and Keys
Accessing Files Within an Encryption Zone
Optimizing Performance for HDFS Transparent Encryption
Managing Encryption Keys and Zones
Validating Hadoop Key Operations
Creating Encryption Zones
Adding Files to an Encryption Zone
Deleting Encryption Zones
Backing Up Encryption Keys
Rolling Encryption Keys
Deleting Encryption Zone Keys
Re-encrypting Encrypted Data Encryption Keys (EDEKs)
Benefits and Capabilities
Prerequisites and Assumptions
Limitations
Re-encrypting an EDEK
Managing Re-encryption Operations
Migrating Keys from a Java KeyStore to Cloudera Navigator Key Trustee Server
Configuring CDP Services for HDFS Encryption
Transparent Encryption Recommendations for HBase
Transparent Encryption Recommendations for Hive
Changed Behavior after HDFS Encryption is Enabled
KMS ACL Configuration for Hive
Transparent Encryption Recommendations for Hue
Transparent Encryption Recommendations for Impala
Transparent Encryption Recommendations for MapReduce and YARN
Transparent Encryption Recommendations for Search
Transparent Encryption Recommendations for Spark
Transparent Encryption Recommendations for Sqoop