[
https://issues.apache.org/jira/browse/DISPATCH-1440?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16946859#comment-16946859
]
ASF GitHub Bot commented on DISPATCH-1440:
------------------------------------------
kgiusti commented on pull request #582: DISPATCH-1440 - Deprecated passwordFile
attribute in sslProfile and m…
URL: https://github.com/apache/qpid-dispatch/pull/582#discussion_r332507603
##########
File path: src/connection_manager.c
##########
@@ -107,31 +107,39 @@ static qd_config_ssl_profile_t
*qd_find_ssl_profile(qd_connection_manager_t *cm,
* Read the file from the password_file location on the file system and
populate password_field with the
* contents of the file.
*/
-static void qd_set_password_from_file(char *password_file, char
**password_field)
+static void qd_set_password_from_file(char *password_file, char
**password_field, qd_log_source_t *log_source)
{
if (password_file) {
FILE *file = fopen(password_file, "r");
- if (file) {
- char buffer[200];
+ if (file == NULL) {
+ //
+ // The global variable errno (found in <errno.h>) contains
information about what went wrong; you can use perror() to print that
information as a readable string
+ //
+ qd_log(log_source, QD_LOG_WARNING, "Unable to open password file
%s", password_file);
Review comment:
I'd recommend including the output of "strerror(errno)" in the log file and
remove the perror stuff (no stderr if in daemon mode):
qd_log(log_source, QD_LOG_WARNING, "Unable to open password file %s, error:
%s", password_file, strerror(errno));
----------------------------------------------------------------
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
For queries about this service, please contact Infrastructure at:
[email protected]
> Deprecate the passwordFile field in sslProfile and consolidate all password
> scenarios to use the password field
> ----------------------------------------------------------------------------------------------------------------
>
> Key: DISPATCH-1440
> URL: https://issues.apache.org/jira/browse/DISPATCH-1440
> Project: Qpid Dispatch
> Issue Type: Improvement
> Components: Container
> Affects Versions: 1.9.0
> Reporter: Ganesh Murthy
> Assignee: Ganesh Murthy
> Priority: Major
>
> Deprecate the passwordFile field and consolidate all password scenarios to
> use the password field. We will use the password options that
> [openssl|https://www.openssl.org/docs/man1.1.1/man1/openssl.html] uses (see
> Pass Phrase Options sections). Going forward, here are three ways to specify
> a password in an sslProfile
>
> {noformat}
> sslProfile {
> caCertFile: .....
> certFile: .....
> # Get the password from the environment variable TLS_SERVER_PASSWORD.
> Note the env: prefix
> password: env:TLS_SERVER_PASSWORD
> OR
> # Get the password from the absolute file path. Note the file: prefix
> password: file:/home/tls/password-file.txt
> OR
> # Specify the actual password. Note the pass: prefix
> password: pass:actual_password
> } {noformat}
> (We will not be supporting the openssl options fd: and stdin
>
>
> While you can still specify the actual password in the password field using
> the pass: prefix, which casual users might want to do, you are also able to
> specify the file path or environment variable for more robust security.
> This change will be backward compatible which means, you will still be able
> to specify the actual password in the password field without the pass:
> prefix. The "literal" prefix will continue to work as well. The passwordFile
> field will be deprecated and eventually removed when we to a major version.
>
--
This message was sent by Atlassian Jira
(v8.3.4#803005)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]