Known issues in FIPS

Known issues in Cloudera Manager FIPS 140-3 mode on RHEL 8.10 cause OpenSSL symlink requirements and HBase ExportSnapshot SSL initialization failures.

OpenSSL HMAC symlink for RHEL8.x FIPS
Cloudera Manager 7.13.2 and lower versions
Cloudera Manager 7.13.1.400, 7.13.2.0 and 7.11.3 CHF15

When running RHEL 8.10 in FIPS mode, you must manually create symbolic links to the OpenSSL libraries on all cluster hosts before initiating a Cloudera Manager cluster installation or upgrade.

This issue affects and only applies to operating system versions other than RHEL 8.10.

cd /usr/lib64
ln -sf /usr/lib64/.libcrypto.so.1.1.1k.hmac /lib64/.libcrypto.so.hmac 
ln -sf /usr/lib64/.libssl.so.1.1.1k.hmac /lib64/.libssl.so.hmac
HBase ExportSnapshot to S3 fails with BCFKS KeyStore error
Cloudera Runtime 7.3.2.10000 with Cloudera Manager 7.13.2 in FIPS 140-3 mode.
In FIPS 140-3 mode, Cloudera Manager creates a BCFKS truststore, but the truststore path and password are not automatically applied to every JVM that participates in the ExportSnapshot workflow. As a result, Secure Sockets Layer (SSL) initialization for cloud storage clients (S3, GCS, ABFS, etc.) can fail, with the BCFKS KeyStore corrupted: MAC calculation failed error message.

The issue can occur in two stages:

  1. The HBase client fails because the truststore-related JVM properties are missing from HBASE_OPTS.
  2. The MapReduce job fails because the YARN map and reduce task JVM options also do not include the required truststore and FIPS-related properties.
  1. Configure the required JVM properties manually so that both the HBase client and the MapReduce task JVMs can load the Cloudera Manager-generated BCFKS truststore.
    Table 1. Required JVM property configurations for HBase and YARN
    Area Required action Reason
    HBase Client Environment safety valve Add the truststore JVM properties to HBASE_OPTS
    HBASE_OPTS="$HBASE_OPTS -Djavax.net.ssl.trustStore=/var/lib/cloudera-scm-agent/agent-cert/cm-auto-global_truststore.jks -Djavax.net.ssl.trustStoreType=bcfks -Djavax.net.ssl.trustStorePassword=BtjodWcTovMMjnvgGC3zgApuFwxyX39Pp2BOf1bnsJw"
    Allows the HBase client process to initialize SSL correctly when accessing S3
    YARN MapReduce Map Task Java Opts Add truststore and FIPS-related JVM properties
    +${IP_JAVA_OPT} -Djavax.net.ssl.trustStore=/var/lib/cloudera-scm-agent/agent-cert/cm-auto-global_truststore.jks -Djavax.net.ssl.trustStoreType=bcfks -Djavax.net.ssl.trustStorePassword=qQK0YwzTFHrF8pQocSJdHwahGoQNSq3TLgaWqnaxIGM -Dcom.safelogic.cryptocomply.fips.approved_only=true --add-modules=com.safelogic.cryptocomply.fips.core --add-modules=bctls --add-exports=java.base/sun.security.provider=com.safelogic.cryptocomply.fips.core
    Allows mapper task JVMs to use the same truststore and crypto configuration
    YARN MapReduce Reduce Task Java Opts Add truststore and FIPS-related JVM properties
    +${IP_JAVA_OPT} -Djavax.net.ssl.trustStore=/var/lib/cloudera-scm-agent/agent-cert/cm-auto-global_truststore.jks -Djavax.net.ssl.trustStoreType=bcfks -Djavax.net.ssl.trustStorePassword=qQK0YwzTFHrF8pQocSJdHwahGoQNSq3TLgaWqnaxIGM -Dcom.safelogic.cryptocomply.fips.approved_only=true --add-modules=com.safelogic.cryptocomply.fips.core --add-modules=bctls --add-exports=java.base/sun.security.provider=com.safelogic.cryptocomply.fips.core
    Allows reducer task JVMs to use the same truststore and crypto configuration
  2. After updating the safety valves, redeploy the client configuration and restart the affected services before rerunning the ExportSnapshot workflow.