Skip to content

Azure plugin certificate too dangerous ? #68

@precbioinf

Description

@precbioinf

Hi,

I have played with the azure plugin and am worried that the certificate
placed into Azure management pool can be very powerful. If a cracker
steals the password and keystore from the elasticsearch.yml, would they
be able to disrupt all the deployments from the same Azure subscription,
even if not related to elasticsearch ? E.g. they could use the keystore,
password to access the subscription fully and delete all the nodes ?

Is there a way to reduce the privilege of the uploaded certificates to
something safer ?

Thanks.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions