Using FIPS with Cloudera products

FIPS 140-3 compliance in Cloudera Base on premises enables validated cryptographic encryption, strong authentication, and data governance through integrated SafeLogic CryptoComply modules.

Cloudera Base on premises achieves FIPS compliance by integrating directly with SafeLogic CryptoComply modules at the host level. To enable FIPS mode, you must configure the underlying host operating system in FIPS mode, install the SafeLogic CryptoComply modules, and configure Cloudera Base on premises to utilize those modules for cryptographic operations.

Cloudera Base on premises 7.1.5 and higher versions are capable of running in a FIPS-compliant mode. Cloudera currently supports a subset of platform components and features running on a FIPS-compliant operating system. Cloudera does not guarantee that the platform components themselves are FIPS 140-3 compliant.

To satisfy FIPS 140-3 and federal compliance standards, Cloudera Base on premises supports FIPS-approved keystores and algorithms with FIPS 140-3 validated cryptographic modules across its security architecture.

Cloudera recommends deploying the following components:

  • Encryption in motion using TLS (Auto-TLS support).
  • Encryption at rest with HDFS Transparent Data Encryption (TDE), Ranger KMS, and Key Trustee Server as the backend keystore.
  • Strong authentication with Kerberos and Apache Knox.
  • Authorization, audit, and data governance with Apache Ranger and Apache Atlas.
Before upgrading, verify FIPS support for the target Cloudera Base on premises and Cloudera Manager versions using the Cloudera support matrix.

Enabling FIPS mode on a RHEL or CentOS-based operating system, configuring the required external databases for FIPS 140-3 compliance are outside the scope of Cloudera documentation. Consult your operating system and database vendor documentation for specific configuration procedures.

For more information about the supported platform components, features and all limitations, see Understanding the prerequisites.