Enabling TLS/SSL for databases

You can enable TLS/SSL for database communication in Cloudera on cloud for existing clusters. When enabling TLS/SSL the client and database communication between the Cloudera on cloud services and the connecting Amazon Relational Database Service (Amazon RDS), Azure Database for PostgreSQL Flexible Server, Google CloudSQL PostgreSQL or embedded PostgreSQL is encrypted using certificates and TLS settings based on the provider or FreeIPA certificate.

Limitations

  • If enabling TLS/SSL for the already existing Data Lake cluster, then TLS/SSL must be enabled to all the Cloudera Data Hub clusters first. This is required if the Cloudera Data Hub contains HMS because that HMS connects to the HMS on the Data Lake cluster.
  • The Cloudera Runtime version on the clusters must be equal to or greater than 7.2.18.
You can check if TLS/SSL is enabled for your Data Lake or Cloudera Data Hub clusters by navigating to the Data Lake or Cloudera Data Hub details page and select Database. The TLS/SSL information is provided under the SSL Enforcement column.
You have the following options to enable TLS/SSL for the databases on your existing clusters:
  • Recreate your Data Lake and Cloudera Data Hub clusters and enable TLS/SSL during cluster creation.
  • Manually enable TLS/SSL for the existing Data Lake and Cloudera Data Hub clusters. Assistance from Cloudera support is required for this option.