Trusting the Ozone STS certificate in the Knox IDBroker truststore

Import the cluster's SCM Local CA into the Knox IDBroker JVM truststore so that the IDBroker can call the Ozone STS and S3 Gateway endpoint over HTTPS when vending temporary credentials to external clients.

The Knox IDBroker calls the Cloudera Object Store (powered by Apache Ozone) STS endpoint over HTTPS. If the certificate authority that signs the Ozone S3 Gateway and STS certificate is not trusted by the IDBroker JVM, the call fails with a PKIX path building failed: unable to find valid certification path to requested target error.

To prevent this error, import the cluster's SCM Local CA (which signs the Ozone S3 Gateway and STS certificate) into the cacerts truststore that the IDBroker AWS SDK uses. Complete this procedure after Configuring the Knox IDBroker for Ozone S3 environments.

Retrieve the SCM Local CA certificate, import it under the ozone-scm-ca alias, and verify the import.

Replace [***OZONE_S3_GATEWAY_HOST***] with the host running the Ozone S3 Gateway, and adjust the JDK path if your cluster uses a different JVM. The awk c==2 selector keeps the second certificate in the chain, which is the SCM Local CA that signs the S3 Gateway and STS certificate.

export S3G=[***OZONE_S3_GATEWAY_HOST***]
export JHOME=/usr/lib/jvm/jdk1.17.0.11.0-openjdk-cloudera

# Grab the full chain and keep the CA (second cert in the chain)
echo | openssl s_client -connect "${S3G}:9881" -showcerts 2>/dev/null \
  | awk '/BEGIN CERT/{c++} c==2,/END CERT/' > /tmp/sts-ca.pem

# Verify that the extracted certificate is the SCM Local CA
openssl x509 -in /tmp/sts-ca.pem -noout -subject -issuer

sudo "$JHOME/bin/keytool" -importcert -noprompt \
  -alias ozone-scm-ca \
  -file /tmp/sts-ca.pem \
  -keystore "$JHOME/lib/security/cacerts" \
  -storepass changeit

"$JHOME/bin/keytool" -list \
  -alias ozone-scm-ca \
  -keystore "$JHOME/lib/security/cacerts" \
  -storepass changeit

Continue with Creating a Data Share.