FIPS integration for JDK 17
Configure FIPS integration for JDK 17 in your Cloudera environment to enable system-wide compliant
cryptographic policies and secure data-at-rest encryption.
Preparing the hosts Prepare cluster hosts for FIPS integration by configuring system entropy, enabling RHEL FIPS mode, and installing JDK 17.Installing Cloudera Manager server Install Cloudera Manager server daemons and configure system environment flags to enable FIPS mode alongside SafeLogic cryptographic path variables for Java environments.Validating the CCJ and CCS installations Validate CryptoComply for Java (CCJ) and CryptoComply for Server (CCS) installations in FIPS mode by verifying kernel module status, active security providers, and maximum cipher key lengths.Installing and configuring databases Configure external databases using FIPS-compliant JDBC drivers and Bouncy Castle FIPS Keystore (BCFKS) formats to establish secure TLS connections across cluster components.Configuring the Spark Cluster Configure the Spark cluster for FIPS environments by adding Cloudera Manager advanced configuration snippet settings to export SafeLogic modules and define Java cryptographic runtime options.