cgivre opened a new pull request, #3089: URL: https://github.com/apache/drill/pull/3089
Potential fix for [https://github.com/apache/drill/security/code-scanning/41](https://github.com/apache/drill/security/code-scanning/41) The correct fix is to increase the RSA key size used during key-pair generation from 1024 to 2048 bits (or higher). This preserves existing behavior (auto-generating a self-signed certificate for the web server) while making the generated key compliant with current minimum recommendations. In `exec/java-exec/src/main/java/org/apache/drill/exec/server/rest/ssl/SslContextFactoryConfigurator.java`, update the `useAutoGeneratedSelfSignedCertificate(...)` method at the key generation block: - Keep algorithm as `RSA`. - Replace `keyPairGenerator.initialize(1024, random);` with `keyPairGenerator.initialize(2048, random);`. No additional imports, methods, or dependencies are required. _Suggested fixes powered by Copilot Autofix. Review carefully before merging._ -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
