[
https://issues.apache.org/jira/browse/HDFS-6134?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=14094485#comment-14094485
]
Sanjay Radia commented on HDFS-6134:
------------------------------------
bq. Regarding webhdfs, it's not a recommended deployment.
The design document in this jira already states that webhdfs just works:
* "This Jira provides encryption for HDFS data at rest and allows any
application to access it via the Hadoop Filesystem Java API, Hadoop libhdfs C
library, or WebHDFS REST API."
* "For HDFS WebHDFS, the DataNodes act as the HDFS client reading/writing files
since that is where encryption/decryption will happen. For HttpFS, the HttpFS
server acts as the HDFS client reading/writing files, since that is where
encryption/decryption will happen."
webhdfs not working is worrying because REST is used by many users who do not
want to deploy hadoop binaries or want to use a non-java client.
Also I do not understand why httpfs works and webhdfs "breaks". Neither will
be running as the end-user and hence neither will allow transparent encryption.
Am I missing something?
> Transparent data at rest encryption
> -----------------------------------
>
> Key: HDFS-6134
> URL: https://issues.apache.org/jira/browse/HDFS-6134
> Project: Hadoop HDFS
> Issue Type: New Feature
> Components: security
> Affects Versions: 3.0.0, 2.3.0
> Reporter: Alejandro Abdelnur
> Assignee: Charles Lamb
> Attachments: HDFS-6134.001.patch, HDFS-6134.002.patch,
> HDFS-6134_test_plan.pdf, HDFSDataatRestEncryption.pdf,
> HDFSDataatRestEncryptionProposal_obsolete.pdf,
> HDFSEncryptionConceptualDesignProposal-2014-06-20.pdf
>
>
> Because of privacy and security regulations, for many industries, sensitive
> data at rest must be in encrypted form. For example: the healthÂcare industry
> (HIPAA regulations), the card payment industry (PCI DSS regulations) or the
> US government (FISMA regulations).
> This JIRA aims to provide a mechanism to encrypt HDFS data at rest that can
> be used transparently by any application accessing HDFS via Hadoop Filesystem
> Java API, Hadoop libhdfs C library, or WebHDFS REST API.
> The resulting implementation should be able to be used in compliance with
> different regulation requirements.
--
This message was sent by Atlassian JIRA
(v6.2#6252)