pradeepagrawal8184 commented on code in PR #1188:
URL: https://github.com/apache/ranger/pull/1188#discussion_r3958635632


##########
embeddedwebserver/src/main/java/org/apache/ranger/server/tomcat/EmbeddedServer.java:
##########
@@ -200,6 +206,32 @@ public void start() {
             ssl.setAttribute("keystorePass", keystorePass);
             ssl.setAttribute("keystoreFile", keystoreFile);
 
+            // Resolve TrustStore & related properties
+            String truststoreCredsAlias = 
EmbeddedServerUtil.getConfig("ranger.service.https.attrib.truststore.credential.alias");
+            String truststorePass  = null;
+
+            if (providerPath != null && truststoreCredsAlias != null) {
+                truststorePass = 
CredentialReader.getDecryptedString(providerPath.trim(), 
truststoreCredsAlias.trim(), 
EmbeddedServerUtil.getConfig("ranger.truststore.file.type", 
RANGER_TRUSTSTORE_FILE_TYPE_DEFAULT));

Review Comment:
   Wrong store type passed to CredentialReader — Truststore password decryption 
uses ranger.truststore.file.type, but the third argument to 
CredentialReader.getDecryptedString() selects how to open the credential 
provider file, not the SSL truststore. The keystore password lookup correctly 
uses ranger.keystore.file.type. If those types differ (e.g. credential store is 
bcfks, SSL truststore is jks), password decryption can fail silently and fall 
back to plaintext. Fix: use keystoreType (already resolved at line 169) instead 
of ranger.truststore.file.type.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to