Hi Team,

We are running PCS 0.12.2 on RHEL 8 with Pacemaker 3.0.1 and Corosync 3.1.10. 
Our security compliance framework (CIS Benchmarks, vendor-specific GPRs) 
requires that all OS accounts have password expiry policies enforced. The 
hacluster account used by pcs cluster auth currently requires a static 
password, which conflicts with this requirement.

We are aware of the long-standing feature request pcs#179 (key-based 
authentication, opened 2018). In March 2022, Tomas Jelinek confirmed it was on 
the backlog with no ETA.

Our questions:
1. Is there any updated timeline for key-based/certificate-based authentication 
in PCS 0.12.x ?
2. Are there any alternative mechanisms in PCS 0.12.x to authenticate nodes 
without relying on the hacluster password (e.g., token-based, certificate 
mutual TLS)?

Our current workaround is periodic automated password rotation with 
re-authentication across all cluster nodes, but this introduces operational 
risk during the rotation window.

Any guidance or roadmap update would be appreciated.

Thanks and Regards,
S Sathish S
_______________________________________________
Manage your subscription:
https://lists.clusterlabs.org/mailman/listinfo/users

ClusterLabs home: https://www.clusterlabs.org/

Reply via email to