Configure Encryption Zone Security
Hive on Tez cannot run some queries on tables stored in encryption zones under certain conditions. When the Hadoop Key Management Server (KMS) connection is SSL-encrypted and a self signed certificate is used, you need to perform a security-related task to allow access.
Perform either of the following actions:
- Install self signed SSL certificate into the cacerts file oon all hosts and skip the steps below.
- Perform the steps below.
- Copy the ssl-client.xml to a directory that is available on all hosts.
- In Cloudera Manager, click . Clusters > Hive on Tez > Configuration.
- Search for the Hive Service Advanced Configuration Snippet (Safety Valve) for hive-site.xml setting.
- In the Hive Service Advanced Configuration Snippet (Safety Valve) for hive-site.xml setting, click +.
tez.aux.urisand in value enter