Hi S Sathish S,
see my comments inline.
On 8/17/26 10:40, S Sathish S via Users wrote:
Hi Team,
We are running PCS 0.12.2 on RHEL 8 with Pacemaker 3.0.1 and Corosync
3.1.10. Our security compliance framework (CIS Benchmarks,
vendor-specific GPRs) requires that all OS accounts have password
expiry policies enforced. The hacluster account used by pcs cluster
auth currently requires a static password, which conflicts with this
requirement.
I believe you could set password expiration dates for hacluster accout
with the `passwd` and `chage` utilites.
We are aware of the long-standing feature request pcs#179 (key-based
authentication, opened 2018). In March 2022, Tomas Jelinek confirmed
it was on the backlog with no ETA.
Our questions:
1. Is there any updated timeline for key-based/certificate-based
authentication in PCS 0.12.x ?
There is no timeline in the foreseeable future for this feature.
2. Are there any alternative mechanisms in PCS 0.12.x to authenticate
nodes without relying on the hacluster password (e.g., token-based,
certificate mutual TLS)?
Token-based authentication is used between cluster nodes after you run
the `pcs
host auth` command using the hacluster password. After running this command,
tokens from the /var/lib/pcsd/known-hosts file are used. You can then
unset the password for the hacluster user account, unless you are using the
legacy pcs-web-ui without Cockpit.
Our current workaround is periodic automated password rotation with
re-authentication across all cluster nodes, but this introduces
operational risk during the rotation window.
Any guidance or roadmap update would be appreciated.
Thanks and Regards,
S Sathish S
_______________________________________________
Manage your subscription:
https://lists.clusterlabs.org/mailman/listinfo/users
ClusterLabs home: https://www.clusterlabs.org/
Regards,
Miroslav
_______________________________________________
Manage your subscription:
https://lists.clusterlabs.org/mailman/listinfo/users
ClusterLabs home: https://www.clusterlabs.org/