Robert Levas created AMBARI-8734:
------------------------------------
Summary: Create a more secure way to obtain and handle KDC
administrator credentials
Key: AMBARI-8734
URL: https://issues.apache.org/jira/browse/AMBARI-8734
Project: Ambari
Issue Type: Improvement
Components: ambari-server
Affects Versions: 2.0.0
Reporter: Robert Levas
Assignee: Robert Levas
Fix For: 2.1.0
The current mechanism for obtaining and handling KDC administrator credentials
is not particularly secure thus allowing any knowledgeable user to potentally
gain access to them.
A new mechanism needs to be put in place to security store this data for at
least the duration of a HTTP session and potentially longer in the event Ambari
allow for long-term storage of this data.
Ideally any solution is generic enough to handle secure data of any type.
--
This message was sent by Atlassian JIRA
(v6.3.4#6332)