Details
-
Improvement
-
Status: Resolved
-
Major
-
Resolution: Duplicate
-
2.0.0
Description
The current mechanism for obtaining and handling KDC administrator credentials is not particularly secure thus allowing any knowledgeable user to potentally gain access to them.
A new mechanism needs to be put in place to security store this data for at least the duration of a HTTP session and potentially longer in the event Ambari allow for long-term storage of this data.
Ideally any solution is generic enough to handle secure data of any type.
Attachments
Issue Links
- duplicates
-
AMBARI-13214 Create a credentials resource used to securely set, update, and remove credentials used by Ambari
- Resolved
- is related to
-
AMBARI-8725 Inject Clusters object into KerberosServerAction
- Resolved
- relates to
-
AMBARI-9014 Design admin principal session expiration handling API call
- Resolved