Uploaded image for project: 'Solr'
  1. Solr
  2. SOLR-7889

Secure ZooKeeper should be easy and the default

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Open
    • Critical
    • Resolution: Unresolved
    • None
    • None
    • security

    Description

      ZooKeeper security is documented at https://cwiki.apache.org/confluence/display/solr/ZooKeeper+Access+Control but is not trivial to setup, see http://search-lucene.com/m/eHNlqr6EnMrP6O

      As we enable more and more security stuff, securing ZK should be easier to do and ideally the default. This is an umbrella for such improvements.

      When all of this is in place and working, perhaps even Solr should refuse to start if Auth/Autz plugins are in use and ZK communication is not properly protected, e.g. require bin/solr start --insecure to override.

      Attachments

        Issue Links

          Activity

            People

              Unassigned Unassigned
              janhoy Jan Høydahl
              Votes:
              1 Vote for this issue
              Watchers:
              4 Start watching this issue

              Dates

                Created:
                Updated: