apache / apache/incubator-pegasus
Support encrypted password file during SASL authentication for ZooKeeper C client
- Dominant language
- C++
- Stars
- 2.1k
- Forks
- 328
- PR merge metrics
- No merged PRs in 30d
Description
# Motivation
Currently, when the meta server connects to ZooKeeper via SASL, the password is stored directly in a plain text file. However, in production environments with high security requirements, storing passwords in plain text files is often not allowed.
# Implementation
Starting from the newly released [ZooKeeper 3.9.4](https://zookeeper.apache.org/doc/r3.9.4/releasenotes.html), the C client [supports decrypting passwords stored in files](https://github.com/apache/zookeeper/pull/2223). Therefore, to enhance security, we need to:
1. Upgrade the ZooKeeper C client dependency used by the server to **3.9.4**.
2. Add configuration options to the ZooKeeper session class to support decrypting the password in the file using a specified encryption scheme before establishing the connection.
# Task list
- [x] https://github.com/apache/incubator-pegasus/pull/2289
- [x] https://github.com/apache/incubator-pegasus/pull/2296
- [x] https://github.com/apache/incubator-pegasus/pull/2293
Contributor guide
Assessment
This issue has not been assessed yet.