<?xml version="1.0" encoding="utf-8" ?>
<!DOCTYPE FL_Course SYSTEM "https://www.flane.de/dtd/fl_course095.dtd"><?xml-stylesheet type="text/xsl" href="https://portal.flane.ch/css/xml-course.xsl"?><course productid="35451" language="fr" source="https://portal.flane.ch/swisscom/fr/xml-course/cloudera-admin-332" lastchanged="2025-07-29T12:18:36+02:00" parent="https://portal.flane.ch/swisscom/fr/xml-courses"><title>Building Secure Cloudera Clusters</title><productcode>ADMIN-332</productcode><vendorcode>CR</vendorcode><vendorname>Cloudera</vendorname><fullproductcode>CR-ADMIN-332</fullproductcode><version>1.0</version><essentials>&lt;p&gt;We recommend a minimum of 3 to 5 years of system administration experience in industry. Students must have proficiency in Linux CLI. Knowledge of Directory Services, Transport Layer Security, Kerberos, and SQL select statements is helpful. Prior experience with Cloudera products is expected, experience with CDH or HDP is sufficient. Students must have access to the Internet to reach Amazon Web Services.&lt;/p&gt;</essentials><audience>&lt;p&gt;This immersion course is intended for Linux Administrators who are taking up roles as CDP Administrators.&lt;/p&gt;</audience><contents>&lt;ul&gt;
&lt;li&gt;Architecture for CDP Clusters&lt;/li&gt;&lt;li&gt;Requirements for an isolated network&lt;/li&gt;&lt;li&gt;Comparison of Active Directory to Identity, Policy, and Audit&lt;/li&gt;&lt;li&gt;Theory and installation of
&lt;ul&gt;
&lt;li&gt;Kerberos&lt;/li&gt;&lt;li&gt;Auto-TLS&lt;/li&gt;&lt;li&gt;Ranger&lt;/li&gt;&lt;li&gt;Atlas&lt;/li&gt;&lt;li&gt;Ranger Key Management Service&lt;/li&gt;&lt;li&gt;Knox Gateway&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;li&gt;Building Ranger Resource Policies&lt;/li&gt;&lt;li&gt;Creating Atlas Classifications&lt;/li&gt;&lt;li&gt;Building Ranger Tag Policies&lt;/li&gt;&lt;/ul&gt;</contents><outline>&lt;h5&gt;Security Management&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;CDP Security Models&lt;/li&gt;&lt;li&gt;CDP Security Pillars&lt;/li&gt;&lt;li&gt;CDP Security Levels&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Project Planning&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;The Importance of Project Planning&lt;/li&gt;&lt;li&gt;Roles and Responsibilities Isolated Networks&lt;/li&gt;&lt;li&gt;Architecture for Network Security&lt;/li&gt;&lt;li&gt;Building an Isolated Network&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Identity Management&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;FreeIPA or Active Directory&lt;/li&gt;&lt;li&gt;Identity Management Architecture&lt;/li&gt;&lt;li&gt;Pluggable Authentication Modules&lt;/li&gt;&lt;li&gt;Lightweight Directory Access Protocol&lt;/li&gt;&lt;li&gt;Cloudera Manager Roles&lt;/li&gt;&lt;li&gt;Managing Super Users&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Quality Controlled Hosts&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;CDP Requirements for Hosts&lt;/li&gt;&lt;li&gt;Recommendations for deployment hosts&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Encrypt Network Traffic&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Theory for Security Protocols&lt;/li&gt;&lt;li&gt;Tools: openssl and keytool&lt;/li&gt;&lt;li&gt;Architecture for Certificate Authorities&lt;/li&gt;&lt;li&gt;Deploying TLS using Auto-TLS&lt;/li&gt;&lt;li&gt;Deploying SASL&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Authentication with Kerberos&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Architecture for Kerberos&lt;/li&gt;&lt;li&gt;Kerberos CLI&lt;/li&gt;&lt;li&gt;Deploying Kerberos&lt;/li&gt;&lt;li&gt;Managing CDP services within Kerberos&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Shared Data Experience (SDX)&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Architecture for Apache Ranger&lt;/li&gt;&lt;li&gt;Deploying Ranger&lt;/li&gt;&lt;li&gt;Deploying Infra Solr&lt;/li&gt;&lt;li&gt;Deploying Atlas&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Data at Rest&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Theory for KMS with KTS&lt;/li&gt;&lt;li&gt;Deploying KMS with KTS&lt;/li&gt;&lt;li&gt;Encrypting Data at Rest&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Single Sign-On with Knox Gateway&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Architecture for Knox Gateway&lt;/li&gt;&lt;li&gt;Installing Knox Gateway&lt;/li&gt;&lt;li&gt;Deploying Knox Gateway SSO&lt;/li&gt;&lt;li&gt;Accessing services through Knox Gateway&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Authorization with Ranger&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Creating Ranger Data Encryption Zones&lt;/li&gt;&lt;li&gt;Creating Ranger Security Zones&lt;/li&gt;&lt;li&gt;Creating Ranger resource policies&lt;/li&gt;&lt;li&gt;Creating Ranger masking policies&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Classify Data with Atlas&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Ranger Policies for Atlas&lt;/li&gt;&lt;li&gt;Searching Atlas&lt;/li&gt;&lt;li&gt;Classifying Data with Tags&lt;/li&gt;&lt;li&gt;Creating Ranger Tag Policies&lt;/li&gt;&lt;li&gt;Creating Ranger Masking Policies&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Audit CDP&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Auditing access on hosts&lt;/li&gt;&lt;li&gt;Auditing users with Ranger&lt;/li&gt;&lt;li&gt;Auditing lineage with Atlas&lt;/li&gt;&lt;li&gt;Troubleshooting with Audits&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Commission CDP&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Validating Security Level 2&lt;/li&gt;&lt;li&gt;Checklist for commissioning CDP&lt;/li&gt;&lt;/ul&gt;&lt;h5&gt;Achieving Compliance&lt;/h5&gt;&lt;ul&gt;
&lt;li&gt;Regulatory Compliance&lt;/li&gt;&lt;li&gt;Roadmap to Security Level 3&lt;/li&gt;&lt;/ul&gt;</outline><essentials_plain>We recommend a minimum of 3 to 5 years of system administration experience in industry. Students must have proficiency in Linux CLI. Knowledge of Directory Services, Transport Layer Security, Kerberos, and SQL select statements is helpful. Prior experience with Cloudera products is expected, experience with CDH or HDP is sufficient. Students must have access to the Internet to reach Amazon Web Services.</essentials_plain><audience_plain>This immersion course is intended for Linux Administrators who are taking up roles as CDP Administrators.</audience_plain><contents_plain>- Architecture for CDP Clusters
- Requirements for an isolated network
- Comparison of Active Directory to Identity, Policy, and Audit
- Theory and installation of

- Kerberos
- Auto-TLS
- Ranger
- Atlas
- Ranger Key Management Service
- Knox Gateway
- Building Ranger Resource Policies
- Creating Atlas Classifications
- Building Ranger Tag Policies</contents_plain><outline_plain>Security Management


- CDP Security Models
- CDP Security Pillars
- CDP Security Levels
Project Planning


- The Importance of Project Planning
- Roles and Responsibilities Isolated Networks
- Architecture for Network Security
- Building an Isolated Network
Identity Management


- FreeIPA or Active Directory
- Identity Management Architecture
- Pluggable Authentication Modules
- Lightweight Directory Access Protocol
- Cloudera Manager Roles
- Managing Super Users
Quality Controlled Hosts


- CDP Requirements for Hosts
- Recommendations for deployment hosts
Encrypt Network Traffic


- Theory for Security Protocols
- Tools: openssl and keytool
- Architecture for Certificate Authorities
- Deploying TLS using Auto-TLS
- Deploying SASL
Authentication with Kerberos


- Architecture for Kerberos
- Kerberos CLI
- Deploying Kerberos
- Managing CDP services within Kerberos
Shared Data Experience (SDX)


- Architecture for Apache Ranger
- Deploying Ranger
- Deploying Infra Solr
- Deploying Atlas
Data at Rest


- Theory for KMS with KTS
- Deploying KMS with KTS
- Encrypting Data at Rest
Single Sign-On with Knox Gateway


- Architecture for Knox Gateway
- Installing Knox Gateway
- Deploying Knox Gateway SSO
- Accessing services through Knox Gateway
Authorization with Ranger


- Creating Ranger Data Encryption Zones
- Creating Ranger Security Zones
- Creating Ranger resource policies
- Creating Ranger masking policies
Classify Data with Atlas


- Ranger Policies for Atlas
- Searching Atlas
- Classifying Data with Tags
- Creating Ranger Tag Policies
- Creating Ranger Masking Policies
Audit CDP


- Auditing access on hosts
- Auditing users with Ranger
- Auditing lineage with Atlas
- Troubleshooting with Audits
Commission CDP


- Validating Security Level 2
- Checklist for commissioning CDP
Achieving Compliance


- Regulatory Compliance
- Roadmap to Security Level 3</outline_plain><duration unit="d" days="4">4 jours</duration><pricelist><price country="DE" currency="USD">3520.00</price></pricelist><miles/></course>