Hi,
Anyone playing with the idea to manage passwords on the node by retrieving them from an externa source like cyberark ?
The idea is to avoid storing passwords in some 'human readable' form in eg. hiera, manifests, catalogs, puppetdb ......
Main concern is security.
We are thinking solving such thing using some custom provider, possible extending existing ones.
Just curious someone has already done some thinking/work about this.
Grts
Johan
--
Johan De Wit
Open Source Consultant -- Open-Future
Red Hat Certified Engineer (805008667232363)
Puppet Certified Professional 2013/2014/2015 (PCP0000006)
Puppet Certified Instructor
blog : http://johan.koewacht.net/ gsm: +32 474 42 40 73
Hi,
Anyone playing with the idea to manage passwords on the node by retrieving them from an externa source like cyberark ?
The idea is to avoid storing passwords in some 'human readable' form in eg. hiera, manifests, catalogs, puppetdb ......
Main concern is security.
Hi Craig,
They are still stored unencrypted in the catalog, which is an issue for us.
Security is a high priority in this case
grts
Johan
--
You received this message because you are subscribed to the Google Groups "Puppet Users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to puppet-users...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/puppet-users/CACxdKhF0Fk6yz%3D3Aw--VFA_DBJ1wGr0Mmfd14SezXUErn4XZNA%40mail.gmail.com.
For more options, visit https://groups.google.com/d/optout.
Recently i stumbled upon a puppetlabs blogpost about conjur. There is also a video of a presentation at puppetconf 2015 about this.
Managing credentials out of band ("out of puppet") seems like a good way to solve the catalog problem.
Thomas
I'm too interested in how people manage credentials without having it in the catalog.
--
You received this message because you are subscribed to the Google Groups "Puppet Users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to puppet-users...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/puppet-users/CACxdKhGrdrciDbSnPNAnGSjfspNP7azB%2BvMofR057dODZ9VL2A%40mail.gmail.com.