Known Issues in Iceberg REST Catalog

Known issues and technical limitations for Cloudera Iceberg REST Catalog are addressed in Cloudera Runtime 7.3.2, its service packs, and cumulative hotfixes.

Known issues identified in Cloudera Runtime 7.3.2.20000 SP2

CDPD-123217: Hive Metastore TLS appears enabled in Cloudera Manager but the metastore log reports SSL disabled
7.3.2.20000
After you enable Auto TLS or configure TLS for the Hive Metastore service in Cloudera Manager, the UI can show Hive Metastore TLS as enabled even when the ENCRYPT_ALL_PORTS feature is not active on the Cloudera Manager server (the CMF_FF_ENCRYPT_ALL_PORTS feature flag). In that case the Hive Metastore process does not enable Thrift SSL, and the metastore log correctly reports Enable SSL = false at startup. The mismatch makes it difficult to confirm TLS when you validate on-premises Data Sharing and Cloudera Iceberg REST Catalog connectivity.
If you require Hive Metastore TLS, set export CMF_FF_ENCRYPT_ALL_PORTS=true and, when you use advanced TLS controls, export CMF_FF_TLS_ADVANCED_CONTROL=true in /etc/default/cloudera-scm-server on the Cloudera Manager server host. Restart the Cloudera Manager server, configure Hive Metastore TLS, redeploy the affected roles, and confirm the metastore log reports SSL enabled. Until a future Cloudera Manager release corrects the UI, treat the metastore log as authoritative when the encrypt-all-ports feature is disabled.