pradeepagrawal8184 commented on code in PR #1188:
URL: https://github.com/apache/ranger/pull/1188#discussion_r3958635632
##########
embeddedwebserver/src/main/java/org/apache/ranger/server/tomcat/EmbeddedServer.java:
##########
@@ -200,6 +206,32 @@ public void start() {
ssl.setAttribute("keystorePass", keystorePass);
ssl.setAttribute("keystoreFile", keystoreFile);
+ // Resolve TrustStore & related properties
+ String truststoreCredsAlias =
EmbeddedServerUtil.getConfig("ranger.service.https.attrib.truststore.credential.alias");
+ String truststorePass = null;
+
+ if (providerPath != null && truststoreCredsAlias != null) {
+ truststorePass =
CredentialReader.getDecryptedString(providerPath.trim(),
truststoreCredsAlias.trim(),
EmbeddedServerUtil.getConfig("ranger.truststore.file.type",
RANGER_TRUSTSTORE_FILE_TYPE_DEFAULT));
Review Comment:
Wrong store type passed to CredentialReader — Truststore password decryption
uses ranger.truststore.file.type, but the third argument to
CredentialReader.getDecryptedString() selects how to open the credential
provider file, not the SSL truststore. The keystore password lookup correctly
uses ranger.keystore.file.type. If those types differ (e.g. credential store is
bcfks, SSL truststore is jks), password decryption can fail silently and fall
back to plaintext. Fix: use keystoreType (already resolved at line 169) instead
of ranger.truststore.file.type.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]