

<!DOCTYPE html>
<html lang="en">
  <head>
    <meta charset="utf-8">
    <meta http-equiv="X-UA-Compatible" content="IE=edge">
    <meta name="viewport" content="width=device-width, initial-scale=1">
    
    <meta name="description" content="Apache Ozone Documentation">

    <title>Documentation for Apache Ozone</title>

    
    <link href="../css/bootstrap.min.css" rel="stylesheet">

    
    <link href="../css/ozonedoc.css" rel="stylesheet">

    
    
    <link href="../swagger-resources/swagger-ui.css" rel="stylesheet">

    
    <script>
      var _paq = window._paq = window._paq || [];
      

       
      _paq.push(['disableCookies']);
      

      _paq.push(['trackPageView']);
      _paq.push(['enableLinkTracking']);
      (function() {
        var u="//analytics.apache.org/";
        _paq.push(['setTrackerUrl', u+'matomo.php']);
        _paq.push(['setSiteId', '34']);
        var d=document, g=d.createElement('script'),
s=d.getElementsByTagName('script')[0];
        g.async=true; g.src=u+'matomo.js'; s.parentNode.insertBefore(g,s);
      })();
    </script>
    

  </head>


<body>


<nav class="navbar navbar-inverse navbar-fixed-top">
  <div class="container-fluid">
    <div class="navbar-header">
      <button type="button" class="navbar-toggle collapsed" data-toggle="collapse" data-target="#sidebar" aria-expanded="false" aria-controls="navbar">
        <span class="sr-only">Toggle navigation</span>
        <span class="icon-bar"></span>
        <span class="icon-bar"></span>
        <span class="icon-bar"></span>
      </button>
      <a href="../zh/index.html" class="navbar-left ozone-logo">
        <img src="../ozone-logo-small.png"/>
      </a>
      <a class="navbar-brand hidden-xs" href="../zh/index.html">
        Apache Ozone/HDDS Documentation
      </a>
      <a class="navbar-brand visible-xs-inline" href="#">Apache Ozone</a>
    </div>
    <div id="navbar" class="navbar-collapse collapse">
      <ul class="nav navbar-nav navbar-right">
        <li><a href="https://github.com/apache/ozone">Source</a></li>
        <li><a href="https://ozone.apache.org">Apache Ozone</a></li>
        <li><a href="https://apache.org">ASF</a></li>
      </ul>
    </div>
  </div>
</nav>


<div class="wrapper">
<div class="container-fluid">
    <div class="row">
        
<div class="col-sm-2 col-md-2 sidebar" id="sidebar">
  <ul class="nav nav-sidebar">
    
    
        
            <li class="">
                
                   <a href="../zh/index.html">
                

                    
                    <span>概述</span>
                </a>
            </li>
        
    
        
            <li class="">
                
                   <a href="../zh/start.html">
                

                    
                    <span>快速入门</span>
                </a>
            </li>
        
    
        
            <li class="">
                <a href="../zh/concept.html">
                    
                    <span>概念</span>
                </a>
                <ul class="nav">
                    
                        <li class="">
                           
                           <a href="../zh/concept/overview.html">概览</a>
                           
                        </li>
                    
                        <li class="">
                           
                           <a href="../zh/concept/ozonemanager.html">Ozone Manager</a>
                           
                        </li>
                    
                        <li class="">
                           
                           <a href="../zh/concept/storagecontainermanager.html">Storage Container Manager</a>
                           
                        </li>
                    
                        <li class="">
                           
                           <a href="../zh/concept/datanodes.html">数据节点</a>
                           
                        </li>
                    
                        <li class="">
                           
                           <a href="../zh/concept/containers.html">Containers</a>
                           
                        </li>
                    
                        <li class="">
                           
                           <a href="../zh/concept/recon.html">Recon</a>
                           
                        </li>
                    
                </ul>
            </li>
        
    
        
            <li class="">
                <a href="../zh/feature.html">
                    
                    <span>特性</span>
                </a>
                <ul class="nav">
                    
                        <li class="">
                           
                           <a href="../zh/feature/decommission.html">Decommissioning</a>
                           
                        </li>
                    
                        <li class="">
                           
                           <a href="../zh/feature/erasurecoding.html">纠删码</a>
                           
                        </li>
                    
                        <li class="">
                           
                           <a href="../zh/feature/om-ha.html">高可用 OM</a>
                           
                        </li>
                    
                        <li class="">
                           
                           <a href="../zh/feature/scm-ha.html">高可用 SCM</a>
                           
                        </li>
                    
                        <li class="">
                           
                           <a href="../zh/feature/dn-merge-rocksdb.html">在DataNode上合并Container的RocksDB</a>
                           
                        </li>
                    
                        <li class="">
                           
                           <a href="../zh/feature/prefixfso.html">基于前缀的文件系统优化</a>
                           
                        </li>
                    
                        <li class="">
                           
                           <a href="../zh/feature/topology.html">拓扑感知能力</a>
                           
                        </li>
                    
                        <li class="">
                           
                           <a href="../zh/feature/quota.html">Ozone 中的配额</a>
                           
                        </li>
                    
                        <li class="">
                           
                           <a href="../zh/feature/recon.html">Recon 服务器</a>
                           
                        </li>
                    
                        <li class="">
                           
                           <a href="../zh/feature/reconfigurability.html">动态加载配置</a>
                           
                        </li>
                    
                </ul>
            </li>
        
    
        
            <li class="active">
                <a href="../zh/security.html">
                    
                    <span>安全</span>
                </a>
                <ul class="nav">
                    
                        <li class="">
                           
                           <a href="../zh/security/secureozone.html">安全化 Ozone</a>
                           
                        </li>
                    
                        <li class="">
                           
                           <a href="../zh/security/securingtde.html">透明数据加密</a>
                           
                        </li>
                    
                        <li class="">
                           
                           <a href="../zh/security/gdpr.html">Ozone 中的 GDPR</a>
                           
                        </li>
                    
                        <li class="">
                           
                           <a href="../zh/security/securingdatanodes.html">安全化 Datanode</a>
                           
                        </li>
                    
                        <li class="">
                           
                           <a href="../zh/security/securings3.html">安全化 S3</a>
                           
                        </li>
                    
                        <li class="">
                           
                           <a href="../zh/security/securityacls.html">Ozone 访问控制列表</a>
                           
                        </li>
                    
                        <li class="">
                           
                           <a href="../zh/security/securitywithranger.html">Apache Ranger</a>
                           
                        </li>
                    
                </ul>
            </li>
        
    
        
            <li class="">
                <a href="../zh/interface.html">
                    
                    <span>编程接口</span>
                </a>
                <ul class="nav">
                    
                        <li class="">
                           
                           <a href="../zh/interface/javaapi.html">Java API</a>
                           
                        </li>
                    
                        <li class="">
                           
                           <a href="../zh/interface/o3fs.html">Ozone 文件系统</a>
                           
                        </li>
                    
                        <li class="">
                           
                           <a href="../zh/interface/csi.html">CSI 协议</a>
                           
                        </li>
                    
                        <li class="">
                           
                           <a href="../zh/interface/s3.html">S3 协议接口</a>
                           
                        </li>
                    
                        <li class="">
                           
                           <a href="../zh/interface/reconapi.html">Recon API</a>
                           
                        </li>
                    
                </ul>
            </li>
        
    
        
            <li class="">
                
                   <a href="../zh/tools.html">
                

                    
                    <span>工具</span>
                </a>
            </li>
        
    
        
            <li class="">
                
                   <a href="../zh/recipe.html">
                

                    
                    <span>使用配方</span>
                </a>
            </li>
        
    
    <li><a href="../design.html"><span><b>Design docs</b></span></a></li>
    <li class="visible-xs"><a href="#">References</a>
    <ul class="nav">
        <li><a href="https://github.com/apache/ozone"><span class="glyphicon glyphicon-new-window" aria-hidden="true"></span> Source</a></li>
        <li><a href="https://ozone.apache.org"><span class="glyphicon glyphicon-new-window" aria-hidden="true"></span> Apache Ozone</a></li>
        <li><a href="https://apache.org"><span class="glyphicon glyphicon-new-window" aria-hidden="true"></span> ASF</a></li>
    </ul></li>
  </ul>

</div>

        <div class="col-sm-10 col-sm-offset-2 col-md-10 col-md-offset-2 main-content">
            <div class="col-md-9">

                

<div class="pull-right">
    
    
    
    <a href="../security.html"><span class="label label-success">English</span></a>
    
    
    
    
</div>

                <h1>安全</h1>
            </div>

            <div class="col-md-9">
                <!---
    Licensed to the Apache Software Foundation (ASF) under one or more
    contributor license agreements.  See the NOTICE file distributed with
    this work for additional information regarding copyright ownership.
    The ASF licenses this file to You under the Apache License, Version 2.0
    (the "License"); you may not use this file except in compliance with
    the License.  You may obtain a copy of the License at

        http://www.apache.org/licenses/LICENSE-2.0

    Unless required by applicable law or agreed to in writing, software
    distributed under the License is distributed on an "AS IS" BASIS,
    WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
    See the License for the specific language governing permissions and
    limitations under the License.
    -->


<div class="jumbotron jumbotron-fluid">
    <div class="container">
        <h3 class="display-4">安全化 Ozone </h3>
        <p class="lead">
            
          Ozone 是一个企业级的安全存储系统，它提供了很多可配置的安全功能，以下页面讨论了如何配置和使用 Ozone 的安全功能。

        </p>
    </div>
</div>
<div class="alert alert-warning" role="alert">
如果你想要深入理解 Ozone 的安全架构，请查看 <a href="https://issues.apache.org/jira/secure/attachment/12911638/HadoopStorageLayerSecurity.pdf">Ozone 安全架构</a>。
</div>
<p>根据不同的需求，安全化 Ozone 有多种可选的步骤。</p>

                
                
                
                

                
                
                <div class="row">
                    
                    <div class="col-sm-6">
                        <div class="card">
                            <div class="card-body">
                                <h2 class="card-title">
                                    
                                    <span class="glyphicon glyphicon-tower"
                                          aria-hidden="true"></span>
                                    
                                    安全化 Ozone
                                </h2>
                                <p class="card-text">简要介绍 Ozone 中的安全概念以及安全化 OM 和 SCM 的步骤。</p>
                                <a href="../zh/security/secureozone.html"
                                   class=" btn btn-primary btn-lg">安全化 Ozone</a>
                            </div>
                        </div>
                    </div>

                    
                

                
                
                    <div class="col-sm-6">
                        <div class="card">
                            <div class="card-body">
                                <h2 class="card-title">
                                    
                                    <span class="glyphicon glyphicon-lock"
                                          aria-hidden="true"></span>
                                    
                                    透明数据加密
                                </h2>
                                <p class="card-text">透明数据加密（Transparent Data Encryption，TDE）以密文形式在磁盘上保存数据，但可以在用户访问的时候自动进行解密。</p>
                                <a href="../zh/security/securingtde.html"
                                   class=" btn btn-primary btn-lg">透明数据加密</a>
                            </div>
                        </div>
                    </div>

                    
                        </div>
                    
                

                
                
                <div class="row">
                    
                    <div class="col-sm-6">
                        <div class="card">
                            <div class="card-body">
                                <h2 class="card-title">
                                    
                                    <span class="glyphicon glyphicon-user"
                                          aria-hidden="true"></span>
                                    
                                    Ozone 中的 GDPR
                                </h2>
                                <p class="card-text">Ozone 中的 GDPR</p>
                                <a href="../zh/security/gdpr.html"
                                   class=" btn btn-primary btn-lg">Ozone 中的 GDPR</a>
                            </div>
                        </div>
                    </div>

                    
                

                
                
                    <div class="col-sm-6">
                        <div class="card">
                            <div class="card-body">
                                <h2 class="card-title">
                                    
                                    <span class="glyphicon glyphicon-th"
                                          aria-hidden="true"></span>
                                    
                                    安全化 Datanode
                                </h2>
                                <p class="card-text">解释安全化 datanode 的不同模式，包括 Kerberos、证书的手动颁发和自动颁发等。</p>
                                <a href="../zh/security/securingdatanodes.html"
                                   class=" btn btn-primary btn-lg">安全化 Datanode</a>
                            </div>
                        </div>
                    </div>

                    
                        </div>
                    
                

                
                
                <div class="row">
                    
                    <div class="col-sm-6">
                        <div class="card">
                            <div class="card-body">
                                <h2 class="card-title">
                                    
                                    <span class="glyphicon glyphicon-cloud"
                                          aria-hidden="true"></span>
                                    
                                    安全化 S3
                                </h2>
                                <p class="card-text">Ozone 支持 S3 协议，并使用 AWS Signature Version 4 protocol which allows a seamless S3 experience.</p>
                                <a href="../zh/security/securings3.html"
                                   class=" btn btn-primary btn-lg">安全化 S3</a>
                            </div>
                        </div>
                    </div>

                    
                

                
                
                    <div class="col-sm-6">
                        <div class="card">
                            <div class="card-body">
                                <h2 class="card-title">
                                    
                                    <span class="glyphicon glyphicon-transfer"
                                          aria-hidden="true"></span>
                                    
                                    Ozone 访问控制列表
                                </h2>
                                <p class="card-text">Ozone 原生的授权模块提供了不需要集成 Ranger 的访问控制列表（ACL）支持。</p>
                                <a href="../zh/security/securityacls.html"
                                   class=" btn btn-primary btn-lg">Ozone 访问控制列表</a>
                            </div>
                        </div>
                    </div>

                    
                        </div>
                    
                

                
                
                <div class="row">
                    
                    <div class="col-sm-6">
                        <div class="card">
                            <div class="card-body">
                                <h2 class="card-title">
                                    
                                    <span class="glyphicon glyphicon-user"
                                          aria-hidden="true"></span>
                                    
                                    Apache Ranger
                                </h2>
                                <p class="card-text">Apache Ranger 是一个用于管理和监控 Hadoop 平台复杂数据权限的框架。</p>
                                <a href="../zh/security/securitywithranger.html"
                                   class=" btn btn-primary btn-lg">Apache Ranger</a>
                            </div>
                        </div>
                    </div>

                    
                
                
            </div>
        </div>
    </div>
</div>
    <div class="push"></div>
</div>



<footer class="footer">
  <div class="container">
    <span class="small text-muted">
      Version: 1.5.0-SNAPSHOT, Last Modified: February 27, 2024 <a class="hide-child link primary-color" href="https://github.com/apache/ozone/commit/7939faf7d6c904bf1e4ad32baa5d6d0c1de19003">7939faf</a>
    </span>
  </div>
</footer>



<script src="../js/jquery-3.5.1.min.js"></script>
<script src="../js/ozonedoc.js"></script>
<script src="../js/bootstrap.min.js"></script>


</body>

</html>