Configuring TLS/SSL for Cloudera Management Service
Starting in Cloudera Manager 7.13.2 SP1 (7.13.2.10000), if you have
already enabled the advanced encryption feature flags (CMF_FF_ENCRYPT_ALL_PORTS
and CMF_FF_TLS_ADVANCED_CONTROL), TLS is automatically activated for Cloudera Management Service roles. If these feature flags are not yet active, you
must enable them before configuring server-side TLS for Cloudera Management Service roles.
For instructions on activating these flags, see Enabling Advanced TLS and Encryption Feature Flags.
While Cloudera recommends using AutoTLS, you can
manually enable, disable, or adjust server-side TLS settings for the following specific Cloudera Management Service roles based on your cluster security requirements:
-
Service Monitor
-
Event Server
-
Alert Publisher
-
Reports Manager
-
Host Monitor
To configure TLS/SSL for the Cloudera Management Service, perform the
following steps:
- In Cloudera Manager, select the Cloudera Management Service from the Clusters drop-down menu.
- Go to the Configuration tab.
- Type
TLSin the Search field to display the Cloudera Management Service TLS/SSL properties. - Edit the properties according to your cluster configuration.
Table 1. Cloudera Management Service TLS/SSL Properties Property Description Enable TLS/SSL for Mgmt Service Enables or disables TLS/SSL encryption for the Cloudera Management Service roles. Supported SSL/TLS versions Specifies the TLS protocol versions the service accepts. By default, this setting inherits the global TLS version configuration. TLS Cipher List Specifies a comma-separated list of active cipher suites to use when TLS/SSL is active. By default, this setting inherits the global TLS cipher list. Mgmt Service TLS/SSL Server Keystore File Location Specifies the local file system path to the JKS keystore file. The keystore must contain the server certificate and the private key for TLS/SSL. Mgmt Service TLS/SSL Server Keystore File Password Specifies the password for accessing the JKS keystore file. - Click Save Changes.
- Restart the Cloudera Management Service roles to apply the new configuration.
