- From: "Kemp, Joseph A. (JKEMP)" <
>
- To: "
" <
>
- Subject: [chef] RE: Re: Securing Knife
- Date: Wed, 6 Nov 2013 22:49:18 +0000
- Accept-language: en-US
My concern is with the pem file. Right now it is basically like storing my
password in the clear in a text file. I need to either add a password to the
private key or I need the chef-server to require the user password to be
provided before it allows access to the chef-server. Why does the chef
server allow a user to perform operations against the server without the
user's password?
-----Original Message-----
From: Mike
[mailto:
Sent: Wednesday, November 06, 2013 5:45 PM
To:
Subject: [chef] Re: Securing Knife
Have individual/personal admin-level pem files - don't share a centralized
one.
knife client create new_person --admin
Ref:
http://docs.opscode.com/chef/knife.html#create
-M
On Wed, Nov 6, 2013 at 5:40 PM, Kemp, Joseph A. (JKEMP)
<
>
wrote:
I am puzzled how to secure the use of knife in open source chef. If
I add a password to the user PEM I am forced to enter the password multiple
times for each knife command. So that's not a very user friendly option.
Someone else suggested storing the pem on an encrypted file
system/device/etc. What is the best practice to provide controlled admin
access to the chef server? It's a little unnerving that someone with a copy
of any admin PEM file gains complete control over your infrastructure. I
feel like I must be missing something.
Thanks,
-Joe
- [chef] Securing Knife, Kemp, Joseph A. (JKEMP), 11/06/2013
- [chef] Re: Securing Knife, Mike, 11/06/2013
- [chef] RE: Re: Securing Knife, Kemp, Joseph A. (JKEMP), 11/06/2013
- [chef] RE: Re: Securing Knife, Kadel-Garcia, Nico, 11/07/2013
- [chef] Re: RE: Re: Securing Knife, Julian C. Dunn, 11/07/2013
- [chef] RE: Re: RE: Re: Securing Knife, Kemp, Joseph A. (JKEMP), 11/07/2013
- [chef] Re: RE: Re: RE: Re: Securing Knife, Ranjib Dey, 11/07/2013
- [chef] Re: Re: RE: Re: RE: Re: Securing Knife, Lamont Granquist, 11/09/2013
- [chef] RE: Re: Re: RE: Re: RE: Re: Securing Knife, Kadel-Garcia, Nico, 11/09/2013
- [chef] Re: RE: Re: Re: RE: Re: RE: Re: Securing Knife, Phil Cryer, 11/09/2013
- [chef] Re: RE: Re: Re: RE: Re: RE: Re: Securing Knife, Lamont Granquist, 11/10/2013
- [chef] RE: Re: RE: Re: Re: RE: Re: RE: Re: Securing Knife, Kemp, Joseph A. (JKEMP), 11/18/2013
Archive powered by MHonArc 2.6.16.