Rate This Document
Findability
Accuracy
Completeness
Readability

Constraints

Understand the OmniShield usage restrictions before configuring the feature.

  • Only 128-bit or 256-bit keys of the AES/GCM/NOPadding algorithm are supported.
  • Only 128-bit keys of the SM4/GCM/NOPadding algorithm are supported.
  • OmniShield does not provide the KMS service or specify the KMS to be used. Determine what KMS to use by yourself.
  • OmniShield does not provide the implementation of the Verifier and Attester in remote attestation. Design the interconnection by yourself.
  • When using the "Encrypting and Decrypting Spark SQL ORC Data Sources Using SM Algorithms" feature of OmniShield, disable the ORC predicate pushdown function of Spark and set the Spark parameter spark.sql.orc.filterPushdown to false.