Trusting the Ozone STS certificate in the Knox IDBroker truststore
Import the cluster's SCM Local CA into the Knox IDBroker JVM truststore so that the IDBroker can call the Ozone STS and S3 Gateway endpoint over HTTPS when vending temporary credentials to external clients.
The Knox IDBroker calls the Cloudera Object Store (powered by Apache Ozone) STS endpoint over
HTTPS. If the certificate authority that signs the Ozone S3 Gateway and STS
certificate is not trusted by the IDBroker JVM, the call fails with a
PKIX path building failed: unable to find valid certification path to
requested target error.
To prevent this error, import the cluster's SCM Local CA (which signs the Ozone S3
Gateway and STS certificate) into the cacerts truststore that the
IDBroker AWS SDK uses. Complete this procedure after Configuring the Knox IDBroker for Ozone S3
environments.
Replace [***OZONE_S3_GATEWAY_HOST***] with the host running
the Ozone S3 Gateway, and adjust the JDK path if your cluster uses a
different JVM. The awk c==2 selector keeps the second
certificate in the chain, which is the SCM Local CA that signs the S3 Gateway
and STS certificate.
export S3G=[***OZONE_S3_GATEWAY_HOST***]
export JHOME=/usr/lib/jvm/jdk1.17.0.11.0-openjdk-cloudera
# Grab the full chain and keep the CA (second cert in the chain)
echo | openssl s_client -connect "${S3G}:9881" -showcerts 2>/dev/null \
| awk '/BEGIN CERT/{c++} c==2,/END CERT/' > /tmp/sts-ca.pem
# Verify that the extracted certificate is the SCM Local CA
openssl x509 -in /tmp/sts-ca.pem -noout -subject -issuer
sudo "$JHOME/bin/keytool" -importcert -noprompt \
-alias ozone-scm-ca \
-file /tmp/sts-ca.pem \
-keystore "$JHOME/lib/security/cacerts" \
-storepass changeit
"$JHOME/bin/keytool" -list \
-alias ozone-scm-ca \
-keystore "$JHOME/lib/security/cacerts" \
-storepass changeit
Continue with Creating a Data Share.
