Known issues and technical limitations for Cloudera Iceberg REST Catalog are addressed in Cloudera Runtime 7.3.2, its service packs, and cumulative hotfixes.
Known issues identified in Cloudera Runtime 7.3.2.20000 SP2
- CDPD-123217: Hive Metastore TLS appears enabled in Cloudera Manager but the metastore log reports SSL disabled
- 7.3.2.20000
- After you enable Auto TLS or configure TLS for the Hive
Metastore service in Cloudera Manager, the UI can show Hive Metastore
TLS as enabled even when the
ENCRYPT_ALL_PORTS feature is not active on
the Cloudera Manager server (the CMF_FF_ENCRYPT_ALL_PORTS feature
flag). In that case the Hive Metastore process does not enable Thrift SSL, and the
metastore log correctly reports Enable SSL = false at startup. The
mismatch makes it difficult to confirm TLS when you validate on-premises Data Sharing
and Cloudera Iceberg REST Catalog connectivity.
- If you require Hive Metastore TLS, set
export CMF_FF_ENCRYPT_ALL_PORTS=true and, when you use advanced TLS
controls, export CMF_FF_TLS_ADVANCED_CONTROL=true in
/etc/default/cloudera-scm-server on the Cloudera Manager server
host. Restart the Cloudera Manager server, configure Hive Metastore TLS, redeploy the
affected roles, and confirm the metastore log reports SSL enabled. Until a future
Cloudera Manager release corrects the UI, treat the metastore log as authoritative when
the encrypt-all-ports feature is disabled.