Cloudera Docs

Protection Schemes

The protection scheme can be selected during encryption using the --protectionScheme flag. During migration, the former protection scheme is specified using the --oldProtectionScheme flag. This distinction allows a set of protected configuration files to be migrated not only to a new key, but to a completely different protection scheme.

  • AES_GCM
  • HASHICORP_VAULT_TRANSIT
  • HASHICORP_VAULT_KV
  • AWS_KMS
  • AWS_SECRETSMANAGER
  • GCP_KMS
Parent topic: Encrypt-Config Tool