Hi Team, We are running PCS 0.12.2 on RHEL 8 with Pacemaker 3.0.1 and Corosync 3.1.10. Our security compliance framework (CIS Benchmarks, vendor-specific GPRs) requires that all OS accounts have password expiry policies enforced. The hacluster account used by pcs cluster auth currently requires a static password, which conflicts with this requirement.
We are aware of the long-standing feature request pcs#179 (key-based authentication, opened 2018). In March 2022, Tomas Jelinek confirmed it was on the backlog with no ETA. Our questions: 1. Is there any updated timeline for key-based/certificate-based authentication in PCS 0.12.x ? 2. Are there any alternative mechanisms in PCS 0.12.x to authenticate nodes without relying on the hacluster password (e.g., token-based, certificate mutual TLS)? Our current workaround is periodic automated password rotation with re-authentication across all cluster nodes, but this introduces operational risk during the rotation window. Any guidance or roadmap update would be appreciated. Thanks and Regards, S Sathish S
_______________________________________________ Manage your subscription: https://lists.clusterlabs.org/mailman/listinfo/users ClusterLabs home: https://www.clusterlabs.org/
