What's New in Apache Knox

New features and functional updates for Apache Knox are introduced in Cloudera Runtime 7.3.2, its service packs, and cumulative hotfixes.

Cloudera Runtime 7.3.2.10000 SP1:

Configurable TLS settings for Knox service discovery

By default, Knox service discovery uses the global TLS cipher and protocol settings when communicating with Cloudera Manager. When Cloudera Manager Server TLS settings differ from the global cluster configuration, you can now configure matching TLS settings on both Cloudera Manager Server and Knox service discovery. You can configure gateway.cloudera.manager.service.discovery.ssl.protocols and gateway.cloudera.manager.service.discovery.ssl.ciphers in Cloudera Manager for Knox service discovery.

For more information about Knox service discovery TLS settings, see Configuring TLS/SSL encryption manually for Apache Knox. For Cloudera Manager Server TLS configuration, see Manually Configuring TLS Encryption for Cloudera Manager.

Global TLS configuration for Apache Knox

Starting in Cloudera Runtime 7.3.2 SP1 (7.3.2.10000), Knox supports Cloudera Manager global TLS protocol and cipher settings. When you enable the CMF_FF_TLS_ADVANCED_CONTROL feature flag, you must configure TLS through the Supported SSL/TLS versions and TLS Cipher List parameters on the Knox service configuration page. When the feature flag is disabled, you must configure TLS through the Knox TLS - Protocols and Knox TLS - Cipher Suites parameters on the Knox service configuration page.

For more information, see Configuring TLS/SSL encryption manually for Apache Knox.

Cloudera Runtime 7.3.2.100 CHF 1

There are no new features in this release.

Cloudera Runtime 7.3.2

Cloudera Runtime 7.3.2 introduces new features of Knox and includes all service packs and cumulative hotfixes from 7.3.1.100 through 7.3.1.706. For a comprehensive record of all updates in Cloudera Runtime 7.3.1.x, see New Features.

SameSite attribute for pac4j session cookies is now configurable
You can now configure the SameSite attribute for pac4j session cookies.
Group impersonation support in Knox
Knox now supports group impersonation, allowing users in specific groups to impersonate other users. For more information, see Configuring Group Impersonation in Knox.
Knox IDBroker integration with HashiCorp Vault
Knox IDBroker now integrates with HashiCorp Vault for AWS credentials management, allowing IDBroker to authenticate with AWS using short-lived credentials from Vault instead of storing long-lived credentials for this purpose. For more information, see Configuring Knox IDBroker with HashiCorp Vault.
Role-level alias management for Knox Gateway and IDBroker
The alias management configuration has been moved from service-level to role-level. Each role now has its own dedicated configuration: gateway_save_alias_command_input for the Knox Gateway role and idbroker_save_alias_command_input for the IDBroker role. Two role-specific commands are now available: Save Alias - Knox Gateway and Save Alias - IDBroker. For more information, see Saving aliases.