Re: Password usage in ssl configuration

2020-11-12 Thread Nico Kruber
Hi Suchithra, I'm not sure you can actually pass passwords in any other way. I'm also not sure this is needed if these are job-/cluster-specific because then, an attacker would have to have access to that first in order to get these credentials. And if the attacker has access to the job/cluster,

Password usage in ssl configuration

2020-10-16 Thread V N, Suchithra (Nokia - IN/Bangalore)
Hello, I have a query regarding the ssl configuration in flink. In flink with ssl enabled, flink-conf.yaml configuration file will contain the cleartext passwords for keystore and truststore files. Suppose if any attacker gains access to this configuration file, using these passwords keystore a