Re: Key Rotation in Data-at-Rest Encryption

2015-06-13 Thread Arun Suresh
Hello Sitaraman, It is the EZ key "version" that is used to generate the EDEK (and which is ultimately stored in the encrypted file's extended attributes '*raw.hdfs.crypto.encryption.info *'), not really the the EZ key itself (which is stored in the director

Key Rotation in Data-at-Rest Encryption

2015-06-13 Thread Sitaraman Vilayannur
HDFSDataatRestEncryption.pdf says the following about key rotation..(please see appended below at the end of the mail) If the existing files do not have their EDEKs reencrypted using the new ezkeyid, how would the existing files be decrypted? That is where is the mapping between files and its EZKey

Build failed in Jenkins: Hadoop-Common-trunk #1525

2015-06-13 Thread Apache Jenkins Server
See Changes: [aajisaka] HADOOP-11971. Move test utilities for tracing from hadoop-hdfs to hadoop-common. Contributed by Masatake Iwasaki. [cmccabe] HDFS-7923. The DataNodes should rate-limit their full block reports by asking the

Build failed in Jenkins: Hadoop-common-trunk-Java8 #227

2015-06-13 Thread Apache Jenkins Server
See Changes: [aajisaka] HADOOP-11971. Move test utilities for tracing from hadoop-hdfs to hadoop-common. Contributed by Masatake Iwasaki. [cmccabe] HDFS-7923. The DataNodes should rate-limit their full block reports by askin