apache / apache/incubator-pegasus

Support encrypted password file during SASL authentication for ZooKeeper C client

Open
#2,292 0 comments 0 reactions 1 assignee Claimed by @empiredan View on GitHub
type/enhancement
Dominant language
C++
Stars
2.1k
Forks
328
PR merge metrics
No merged PRs in 30d

Description

# Motivation

Currently, when the meta server connects to ZooKeeper via SASL, the password is stored directly in a plain text file. However, in production environments with high security requirements, storing passwords in plain text files is often not allowed.

# Implementation

Starting from the newly released [ZooKeeper 3.9.4](https://zookeeper.apache.org/doc/r3.9.4/releasenotes.html), the C client [supports decrypting passwords stored in files](https://github.com/apache/zookeeper/pull/2223). Therefore, to enhance security, we need to:

1. Upgrade the ZooKeeper C client dependency used by the server to **3.9.4**.
2. Add configuration options to the ZooKeeper session class to support decrypting the password in the file using a specified encryption scheme before establishing the connection.

# Task list

- [x] https://github.com/apache/incubator-pegasus/pull/2289
- [x] https://github.com/apache/incubator-pegasus/pull/2296
- [x] https://github.com/apache/incubator-pegasus/pull/2293

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.