Known issues in FIPS
Known issues in Cloudera Manager FIPS 140-3 mode on RHEL 8.10 cause OpenSSL symlink requirements and HBase ExportSnapshot SSL initialization failures.
- OpenSSL HMAC symlink for RHEL8.x FIPS
- Cloudera Manager 7.13.2 and lower versions
- Cloudera Manager 7.13.1.400, 7.13.2.0 and 7.11.3 CHF15
-
When running RHEL 8.10 in FIPS mode, you must manually create symbolic links to the OpenSSL libraries on all cluster hosts before initiating a Cloudera Manager cluster installation or upgrade.
This issue affects and only applies to operating system versions other than RHEL 8.10.
-
cd /usr/lib64 ln -sf /usr/lib64/.libcrypto.so.1.1.1k.hmac /lib64/.libcrypto.so.hmac ln -sf /usr/lib64/.libssl.so.1.1.1k.hmac /lib64/.libssl.so.hmac
- HBase ExportSnapshot to S3 fails with BCFKS KeyStore error
- Cloudera Runtime 7.3.2.10000 with Cloudera Manager 7.13.2 in FIPS 140-3 mode.
- In FIPS 140-3 mode, Cloudera Manager creates a
BCFKS truststore, but the truststore path and password are not automatically applied to every
JVM that participates in the ExportSnapshot workflow. As a result, Secure Sockets Layer (SSL)
initialization for cloud storage clients (S3, GCS, ABFS, etc.) can fail, with the BCFKS KeyStore corrupted: MAC calculation failed error
message.
The issue can occur in two stages:
- The HBase client fails because the truststore-related JVM properties are missing from
HBASE_OPTS. - The MapReduce job fails because the YARN map and reduce task JVM options also do not include the required truststore and FIPS-related properties.
- The HBase client fails because the truststore-related JVM properties are missing from
-
- Configure the required JVM properties manually so that both the HBase client and the
MapReduce task JVMs can load the Cloudera Manager-generated BCFKS truststore.
Table 1. Required JVM property configurations for HBase and YARN Area Required action Reason HBase Client Environment safety valve Add the truststore JVM properties to HBASE_OPTSHBASE_OPTS="$HBASE_OPTS -Djavax.net.ssl.trustStore=/var/lib/cloudera-scm-agent/agent-cert/cm-auto-global_truststore.jks -Djavax.net.ssl.trustStoreType=bcfks -Djavax.net.ssl.trustStorePassword=BtjodWcTovMMjnvgGC3zgApuFwxyX39Pp2BOf1bnsJw"Allows the HBase client process to initialize SSL correctly when accessing S3 YARN MapReduce Map Task Java Opts Add truststore and FIPS-related JVM properties +${IP_JAVA_OPT} -Djavax.net.ssl.trustStore=/var/lib/cloudera-scm-agent/agent-cert/cm-auto-global_truststore.jks -Djavax.net.ssl.trustStoreType=bcfks -Djavax.net.ssl.trustStorePassword=qQK0YwzTFHrF8pQocSJdHwahGoQNSq3TLgaWqnaxIGM -Dcom.safelogic.cryptocomply.fips.approved_only=true --add-modules=com.safelogic.cryptocomply.fips.core --add-modules=bctls --add-exports=java.base/sun.security.provider=com.safelogic.cryptocomply.fips.coreAllows mapper task JVMs to use the same truststore and crypto configuration YARN MapReduce Reduce Task Java Opts Add truststore and FIPS-related JVM properties +${IP_JAVA_OPT} -Djavax.net.ssl.trustStore=/var/lib/cloudera-scm-agent/agent-cert/cm-auto-global_truststore.jks -Djavax.net.ssl.trustStoreType=bcfks -Djavax.net.ssl.trustStorePassword=qQK0YwzTFHrF8pQocSJdHwahGoQNSq3TLgaWqnaxIGM -Dcom.safelogic.cryptocomply.fips.approved_only=true --add-modules=com.safelogic.cryptocomply.fips.core --add-modules=bctls --add-exports=java.base/sun.security.provider=com.safelogic.cryptocomply.fips.coreAllows reducer task JVMs to use the same truststore and crypto configuration - After updating the safety valves, redeploy the client configuration and restart the affected services before rerunning the ExportSnapshot workflow.
- Configure the required JVM properties manually so that both the HBase client and the
MapReduce task JVMs can load the Cloudera Manager-generated BCFKS truststore.
