Configuring SSL/TLS certificate exchange between two Cloudera Manager instances
You must manually set up an SSL/TLS certificate exchange between two Cloudera Manager
instances that manage source and target cluster respectively. Replication Manager uses this
information to set up the peers for secure data replication.
When the source Cloudera Manager is configured for high availability and is
Auto-TLS enabled, the certificate exchange is initiated from the source cluster to
the target cluster where the certificate is exported from the load balancer node of
the source cluster.
List the contents of the keystore file located in the source cluster Cloudera
Manager.
Run steps 1 and 2 in the target cluster Cloudera Manager, and then copy the
cert.txt file to all the hosts in the source cluster
Cloudera Manager securely, and import the certificate into the keystore file on
all the hosts of the source cluster Cloudera Manager (steps 3 and 4).
Perform this step only for Ozone replication policies.
Import the S3G CA certificate from the cluster to the local JDK path using the
following commands:
Run the following command on all the nodes of the source cluster: