[
https://issues.apache.org/jira/browse/RANGER-5715?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Dineshkumar Yadav updated RANGER-5715:
--------------------------------------
Fix Version/s: 3.0.0
> Improve Ranger Admin HTTPS/TLS startup logging for keystore/alias
> misconfiguration
> ----------------------------------------------------------------------------------
>
> Key: RANGER-5715
> URL: https://issues.apache.org/jira/browse/RANGER-5715
> Project: Ranger
> Issue Type: Improvement
> Components: admin, audit, kms, tagsync, usersync
> Reporter: Eoin McDonnell
> Assignee: Eoin McDonnell
> Priority: Major
> Fix For: 3.0.0
>
> Time Spent: 20m
> Remaining Estimate: 0h
>
> When Ranger Admin fails to start listening on the configured HTTPS port due
> to TLS / keystore problems (for example, a configured keystore key alias that
> does not exist in the keystore, an unreadable keystore, or an incorrect
> keystore password), troubleshooting from Ranger Admin logs is difficult.
> In some cases, the more noticeable log message is unrelated to TLS, such as:
> ERROR org.apache.ranger.common.RangerConfigUtil: webapp URL is not set.
> Please ranger.externalurl property
> That message does not clearly indicate a TLS/keystore configuration problem.
> Proposal:
> 1. During HTTPS connector startup in EmbeddedServer, validate keystore
> accessibility and that the configured keystore key alias exists in the
> keystore (when configured).
> 2. Emit clear ERROR logs that identify TLS/keystore misconfiguration (without
> logging secrets), including that HTTPS may not bind / the UI may not listen
> on the configured port.
> 3. Apply the same validation/logging pattern to other Ranger components that
> use a similar EmbeddedServer HTTPS setup (for example tagsync,
> unixauthservice, audit server EmbeddedServer copies), where applicable.
> Primary code area:
> embeddedwebserver/.../EmbeddedServer.java
--
This message was sent by Atlassian Jira
(v8.20.10#820010)