Working with an HSM

How to integrate Cloudera Data Encryption components to provide enterprise data encryption solutions.

Ranger KMS and Key Trustee Server (KTS)

Consists of Ranger KMS providing enterprise-grade key management and the Key Trustee Server key store that stores and manages cryptographic keys and other security artifacts.

  1. Install Ranger KMS backed by KTS using CM > Administration > Security > HDFS Encryption Wizard.

Ranger KMS, KTS, and Key HSM

Consists of Ranger KMS, KTS and Key HSM which provides seamless integration of all Cloudera encryption components with a HSM added.

  1. Install Ranger KMS backed by KTS using CM > Administration > Security > HDFS Encryption Wizard.
  2. Obtain and Integrate one of the following hardware security modules (HSM) supplied by a vendor.
    • Luna 6 or 7
    • CipherTrust
    • GCP Cloud HSM
    • Azure Key Vault