Uploaded image for project: 'Ranger'
  1. Ranger
  2. RANGER-723

Ranger-KMS – CloudHSM Integration

    XMLWordPrintableJSON

Details

    • New Feature
    • Status: Open
    • Minor
    • Resolution: Unresolved
    • 0.5.0
    • None
    • kms, Ranger
    • None

    Description

      Integrate Ranger KMS with CloudHSM to manage master keys.

      Currently Ranger KMS uses the database (rangerkms.ranger_masterkey) to store the master key.
      This Master key is encrypted using a property "KMS_MASTER_KEY_PASSWD".

      It would be nice if we can use CloudHSM instead of using "KMS_MASTER_KEY_PASSWD" to encrypt the master key.

      This will add an extra layer in the Key Hierarchy.

      Attached is the high level architecture of the current Hadoop KMS and the proposed change to integrate with CloudHSM.

      Attachments

        1. Hadoop KMS.png
          33 kB
          Varun Rao
        2. Ranger KMS - CloudHSM integration.png
          40 kB
          Varun Rao

        Activity

          People

            varunraob Varun Rao
            varunraob Varun Rao
            Votes:
            1 Vote for this issue
            Watchers:
            9 Start watching this issue

            Dates

              Created:
              Updated: