AMBARI-24894. Sensitive service configuration values should be decrypted when processing the Ambari agent command script, if enabled (amagyar)#2613
Conversation
…ted when processing the Ambari agent command script, if enabled (amagyar)
|
Refer to this link for build results (access rights to CI server needed): |
ambari-common/src/main/python/resource_management/libraries/script/config_dictionary.py
Outdated
Show resolved
Hide resolved
ambari-server/src/main/java/org/apache/ambari/server/security/encryption/Encryptor.java
Show resolved
Hide resolved
ambari-server/src/test/java/org/apache/ambari/server/agent/TestHeartbeatHandler.java
Outdated
Show resolved
Hide resolved
…ript/config_dictionary.py Co-Authored-By: zeroflag <m.magyar3@gmail.com>
|
Refer to this link for build results (access rights to CI server needed): |
…ted when processing the Ambari agent command script, if enabled (amagyar)
…ted when processing the Ambari agent command script, if enabled (amagyar)
|
Refer to this link for build results (access rights to CI server needed): |
|
Refer to this link for build results (access rights to CI server needed): |
…ted when processing the Ambari agent command script, if enabled (amagyar)
|
Refer to this link for build results (access rights to CI server needed): |
…ted when processing the Ambari agent command script, if enabled (amagyar)
|
Refer to this link for build results (access rights to CI server needed): |
…ted when processing the Ambari agent command script, if enabled (amagyar)
|
Refer to this link for build results (access rights to CI server needed): |
|
retest this please |
|
Refer to this link for build results (access rights to CI server needed): |
|
retest this please |
ambari-common/src/main/python/resource_management/libraries/script/config_dictionary.py
Outdated
Show resolved
Hide resolved
ambari-common/src/main/python/resource_management/libraries/script/config_dictionary.py
Outdated
Show resolved
Hide resolved
ambari-server/src/main/java/org/apache/ambari/server/agent/stomp/AgentConfigsHolder.java
Outdated
Show resolved
Hide resolved
|
retest this please |
|
Refer to this link for build results (access rights to CI server needed): |
|
retest this please |
|
Refer to this link for build results (access rights to CI server needed): |
ambari-server/src/main/java/org/apache/ambari/server/agent/stomp/AgentConfigsHolder.java
Outdated
Show resolved
Hide resolved
…ted when processing the Ambari agent command script, if enabled (amagyar)
|
Refer to this link for build results (access rights to CI server needed): |
…ted when processing the Ambari agent command script, if enabled (amagyar)
|
Refer to this link for build results (access rights to CI server needed): |
|
retest this please |
|
Refer to this link for build results (access rights to CI server needed): |
…ted when processing the Ambari agent command script, if enabled (amagyar) (apache#2613)
What changes were proposed in this pull request?
The sensitive data in ambari-agent config updates should be encrypted. The ambari-server generates an encrpytion key which is stored persistently in the credential store.
The python 3rd party crypto library (pycryptodome) is not yet added to this PR.
How was this patch tested?
changed the encryption key and restarted ambari server
checked that a config update was sent to the ambari agent
changed the value of an encrypted property
checked that a config update was sent to the ambari agent