How can encrypt the kafka password in jaas configuration file

Viewed 308

I am new to Kafka, please let me know how can we encrypt the password used in jaas configuration file. My config example.

KafkaClient { 

  org.apache.kafka.common.security.plain.PlainLoginModule required

  username="username"

  password="password";

};

I am using VM arguments to fetch the config file in the spring boot application.

1 Answers

You can't. The next best, more robust algorithm that you might want to consider is SASL SCRAM:

Salted Challenge Response Authentication Mechanism (SCRAM) is a family of SASL mechanisms that addresses the security concerns with traditional mechanisms that perform username/password authentication like PLAIN and DIGEST-MD5. The mechanism is defined in RFC 5802. Kafka supports SCRAM-SHA-256 and SCRAM-SHA-512 which can be used with TLS to perform secure authentication. The username is used as the authenticated Principal for configuration of ACLs etc. The default SCRAM implementation in Kafka stores SCRAM credentials in Zookeeper and is suitable for use in Kafka installations where Zookeeper is on a private network. Refer to Security Considerations for more details.

IMPORTANT: If you decide to go ahead, make sure you are using TLS, else there is little to no benefits.

Related