Security

If you would like to understand Ozone’s security architecture at a greater depth, please take a look at

Depending on your needs, there are multiple optional steps in securing ozone.

Transparent Data Encryption

TDE allows data on the disks to be encrypted-at-rest and automatically decrypted during access.

Support to implement the “Right to be Forgotten” requirement of GDPR

Securing Datanodes

Secure HTTP web-consoles for Ozone services

Securing S3

Ozone supports S3 protocol, and uses AWS Signature Version 4 protocol which allows a seamless S3 experience.

Apache Ranger

Apache Ranger is a framework to enable, monitor and manage comprehensive data security across the Hadoop platform.