Chinmay N Hegde created RANGER-5776:
---------------------------------------

             Summary: Prevent DB2HSM migration tool from overwriting existing 
keys in HSM
                 Key: RANGER-5776
                 URL: https://issues.apache.org/jira/browse/RANGER-5776
             Project: Ranger
          Issue Type: Bug
          Components: Ranger
    Affects Versions: 3.0.0
            Reporter: Chinmay N Hegde
            Assignee: Chinmay N Hegde


Currently, when the master key is migrated from the KMS DB to Luna HSM using 
the migration tool ({*}DB2HSMMKUtil{*}), it silently overwrites any existing 
key present in the HSM. This overwrite should never happen, as it could lead to 
loss of data if the HSM already holds the active master key.

The fix must be added to check the presence of alias in HSM before writing to 
the HSM. If the alias is already present, the write is skipped and a warning is 
logged. 
This brings the behaviour in sync with how *HSM2DBMKUtil* works.
(Note: This also needs to be fixed onĀ *RangerSafenetKeySecure* side)



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to