accumulo-notifications mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Josh Elser (JIRA)" <j...@apache.org>
Subject [jira] [Commented] (ACCUMULO-2432) MAC should have an option for creating it's own ssl certs
Date Wed, 18 Jun 2014 20:30:25 GMT

    [ https://issues.apache.org/jira/browse/ACCUMULO-2432?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=14036325#comment-14036325
] 

Josh Elser commented on ACCUMULO-2432:
--------------------------------------

While you're still correct that the "details" involved with generating and using the keys
is valid, that does not imply that the testing against Accumulo configured to use "some" SSL
configuration is only valid within the scope of those "details". The encryption algorithm,
signing algorithm, keysize, etc used to generate my certs will likely not affect me at the
application level (assuming that I have the appropriate JCE stuff available, I imagine). Please
enlighten me if this is not the case

We can make a "reasonable" set of default choices (e.g. like what is already done by CertUtils).
IMO, by not providing any direction to users in how to use this feature will just keep them
from ever wanting to use it. I still don't see why we cannot provide some "InsecureSecureEnvironment"
in which we generate security material, for the purposes of running a test against the system.
If we can encourage people to use the feature in some way/shape/form, we're much more likely
to actually get adoption.

To your point, if some detail in an environment does cause them trouble, they can then write
a test that sets up their environment in some relevant way to help them prevent a regression
of the problem. We can still provide a starting point. 

> MAC should have an option for creating it's own ssl certs
> ---------------------------------------------------------
>
>                 Key: ACCUMULO-2432
>                 URL: https://issues.apache.org/jira/browse/ACCUMULO-2432
>             Project: Accumulo
>          Issue Type: Bug
>          Components: mini
>            Reporter: John Vines
>              Labels: newbie
>             Fix For: 1.7.0
>
>
> Currently ssl certs must be generated prior to starting mac, and passed in. We should
find a way to make that as seamless as possible.



--
This message was sent by Atlassian JIRA
(v6.2#6252)

Mime
View raw message