Also available as:
loading table of contents...

Installing the JCE

Before enabling Kerberos in the cluster, you must deploy the Java Cryptography Extension (JCE) security policy files on the Ambari Server and on all hosts in the cluster.


If you are using Oracle JDK, you must distribute and install the JCE on all hosts in the cluster, including the Ambari Server. Be sure to restart Ambari Server after installing the JCE. If you are using OpenJDK, some distributions of the OpenJDK come with unlimited strength JCE automatically and therefore, installation of JCE is not required.

  1. On the Ambari Server, obtain the JCE policy file appropriate for the JDK version in your cluster.

  2. Save the policy file archive in a temporary location.

  3. On Ambari Server and on each host in the cluster, add the unlimited security policy JCE jars to $JAVA_HOME/jre/lib/security/.

    For example, run the following to extract the policy jars into the JDK installed on your host:

    unzip -o -j -q -d /usr/jdk64/jdk1.8.0_60/jre/lib/security/
  4. Restart Ambari Server.