cgivre opened a new pull request, #3089:
URL: https://github.com/apache/drill/pull/3089

   Potential fix for 
[https://github.com/apache/drill/security/code-scanning/41](https://github.com/apache/drill/security/code-scanning/41)
   
   The correct fix is to increase the RSA key size used during key-pair 
generation from 1024 to 2048 bits (or higher). This preserves existing behavior 
(auto-generating a self-signed certificate for the web server) while making the 
generated key compliant with current minimum recommendations.
   
   In 
`exec/java-exec/src/main/java/org/apache/drill/exec/server/rest/ssl/SslContextFactoryConfigurator.java`,
 update the `useAutoGeneratedSelfSignedCertificate(...)` method at the key 
generation block:
   - Keep algorithm as `RSA`.
   - Replace `keyPairGenerator.initialize(1024, random);` with 
`keyPairGenerator.initialize(2048, random);`.
   
   No additional imports, methods, or dependencies are required.
   
   
   _Suggested fixes powered by Copilot Autofix. Review carefully before 
merging._
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to