Uploaded image for project: 'Ambari'
  1. Ambari
  2. AMBARI-25141

LDAP password in cleartext in ldap-password.dat file after encrypting passwords

    XMLWordPrintableJSON

Details

    Description

      In 2.7.x we store LDAP password within its own file; however the content of that file is not encrypted even if password encryption is on. To approach this issue the following should be done:

      • in case password encryption is enabled we will encrypt the LDAP password in the credential store and write the corresponding CS alias in the LDAP password file (just like we do with other passwords inĀ ambari.properties)
      • in case the password encryption is disabled we will write the raw password in the LDAP password file

      In both cases an additional level of security can be achieved by setting the appropriate user/group access on the file system to the LDAP password file.

      Attachments

        Issue Links

          Activity

            People

              smolnar Sandor Molnar
              smolnar Sandor Molnar
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Time Tracking

                  Estimated:
                  Original Estimate - Not Specified
                  Not Specified
                  Remaining:
                  Remaining Estimate - 0h
                  0h
                  Logged:
                  Time Spent - 0.5h
                  0.5h