What's New in Ranger KMS

Learn about the new features of Ranger KMS in Cloudera Runtime 7.3.2.0, its service packs and cumulative hotfixes.

Cloudera Runtime 7.3.2.10000 SP1

Ranger KMS supports new Key Derivation Functions (KDFs) and ciphers
Ranger KMS now supports configurable Key Derivation Functions (KDFs) and ciphers for Master key and Zone key encryption. KMS uses AES-256 for all key generation and allows administrators to configure cryptographic parameters for enhanced security. To understand and configure the supported KDFs and ciphers Configuration of cryptographic parameters.
TLS 1.3 support
Ranger KMS supports TLS 1.3 for stronger security and compliance.

Cloudera Runtime 7.3.2.100 CHF 1

There are no new features in this release.

Cloudera Runtime 7.3.2

Ranger KMS in a federated deployment
Ranger KMS can now be deployed in a federated cluster for key management.
A data cluster is a cluster where application and data processing occur. The cluster stores and processes actual datasets but does not directly manage encryption keys. A security cluster (with the Ranger KMS service installed) is managed separately from the data cluster. It manages the key lifecycle operations (for example, generation, rotation, storage). This separation of tasks enhances security by isolating the administration of the data and security clusters.
For more details, see Installing Ranger KMS in a federated deployment.