[jira] [Created] (FLINK-21196) Sensitive information(password) is not masked in configuration file

classic Classic list List threaded Threaded
1 message Options
Reply | Threaded
Open this post in threaded view
|

[jira] [Created] (FLINK-21196) Sensitive information(password) is not masked in configuration file

Shang Yuanchun (Jira)
Suchithra V N created FLINK-21196:
-------------------------------------

             Summary: Sensitive information(password) is not masked in configuration file
                 Key: FLINK-21196
                 URL: https://issues.apache.org/jira/browse/FLINK-21196
             Project: Flink
          Issue Type: Bug
          Components: Deployment / Scripts
    Affects Versions: 1.11.3, 1.10.0
            Reporter: Suchithra V N


When ssecurit settings are enabled in flink configuration passwords information will be wriiten in flink-conf.yaml file as a plain text. If any attacker is able to access this file can use these paswords to decrypt the files. Hence secure mechanism is required to mask these senstive information from flink-conf.yaml file.



--
This message was sent by Atlassian Jira
(v8.3.4#803005)