Return-Path: X-Original-To: apmail-hbase-issues-archive@www.apache.org Delivered-To: apmail-hbase-issues-archive@www.apache.org Received: from mail.apache.org (hermes.apache.org [140.211.11.3]) by minotaur.apache.org (Postfix) with SMTP id 9F5F31174B for ; Thu, 28 Aug 2014 23:01:09 +0000 (UTC) Received: (qmail 51256 invoked by uid 500); 28 Aug 2014 23:01:09 -0000 Delivered-To: apmail-hbase-issues-archive@hbase.apache.org Received: (qmail 51205 invoked by uid 500); 28 Aug 2014 23:01:09 -0000 Mailing-List: contact issues-help@hbase.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Delivered-To: mailing list issues@hbase.apache.org Received: (qmail 51192 invoked by uid 99); 28 Aug 2014 23:01:09 -0000 Received: from arcas.apache.org (HELO arcas.apache.org) (140.211.11.28) by apache.org (qpsmtpd/0.29) with ESMTP; Thu, 28 Aug 2014 23:01:09 +0000 Date: Thu, 28 Aug 2014 23:01:09 +0000 (UTC) From: "Larry McCay (JIRA)" To: issues@hbase.apache.org Message-ID: In-Reply-To: References: Subject: [jira] [Updated] (HBASE-11810) Access SSL Passwords through Credential Provider API MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 7bit X-JIRA-FingerPrint: 30527f35849b9dde25b450d4833f0394 [ https://issues.apache.org/jira/browse/HBASE-11810?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Larry McCay updated HBASE-11810: -------------------------------- Status: Open (was: Patch Available) > Access SSL Passwords through Credential Provider API > ---------------------------------------------------- > > Key: HBASE-11810 > URL: https://issues.apache.org/jira/browse/HBASE-11810 > Project: HBase > Issue Type: Improvement > Components: security > Reporter: Larry McCay > Assignee: Larry McCay > Attachments: HBASE_11810.patch > > > HADOOP-10607 introduced the credential provider API for allowing passwords and other sensitive configuration items to be stored in an external provider. > RESTServer is accessing passwords stored in clear text in Configuration through the standard get() method. By using the new Configuration.getPassword method instead, the credential provider API will be checked first then fall back to clear text - when allowed. -- This message was sent by Atlassian JIRA (v6.2#6252)