If you are deploying the Secrets plugin, you are storing all of your credentials in the external secrets manager. In this case you do not need to use an encrypted password, so skip this step. See Implementing the Secrets Plugin.
Prior to installing the Nok Nok Servers and their components, create a custom password encryption key. Next, run a script which uses that key to encrypt passwords in your installation.
Create Your Custom Password Encryption Key
This step is mandatory for production installations but optional for development installations.
By default, the Authentication Server uses an internal static key for encryption that is the same across different installations of the Authentication Server. You must replace the default key with a custom key. Once you have provisioned the key, assign it to the NNL_PKEY system environment variable so Nok Nok systems and shell scripts can access the key. If you plan to install several Authentication Servers, use the same key.
Use a script called nnl-key-generator.sh located in mfas/admin/bin. The script doesn't take any arguments, below is sample output:
[nnl@nnl-test-server bin]$ ./nnl-key-generator.sh
Running nnl-key-generator.sh ...
Generated encryption key : EPlk_WqHAIaMTeJWAt5wHgIn a production installation you need to create an environment variable, called NNL_PKEY, on all Nok Nok nodes. Assign the encryption key to this variable.
For example:
export NNL_PKEY=EPlk_WqHAIaMTeJWAt5wHgNNL_PKEY must be set before performing any of the following:
Encrypting a password with nnl-encrypt-password.sh
Running any of the Nok Nok command-line tools like nnl-mgmt.sh
Starting Tomcat
Encrypt Password
Encrypt the following property in nnl-install.properties file, if you are using it:
Property | Description |
|---|---|
DB_ENCRYPTED_USER_PASSWD_ENV | Operational Database user password |
Using nnl-encrypt-password.sh
If you are editing nnl-install.properties, exit the editor because the script modifies this file. Run the nnl-encrypt-password.sh script to generate an encrypted password or server key.
The script takes one parameter: the property name from nnl-install.properties that you want to encrypt.
You are prompted for the value to encrypt.
The script automatically inserts the encrypted value into nnl-install.properties.
An example to encrypt a database password intended for the DB_ENCRYPTED_USER_PASSWD_ENV property is shown below:
cd <NNL_HOME>/install
./nnl-encrypt-password.sh DB_ENCRYPTED_USER_PASSWD_ENV
Running nnl-encrypt-password.sh ...
Found DB_ENCRYPTED_USER_PASSWD_ENV in nnl-install.properties.
- Enter the value to be encrypted:
- Re-enter the value to be encrypted:
The two entries matched. Generating the encrypted value.
Encrypted value: 7L_vFEs6eR9b2J-4JoTJHyZD-8a5h6vYxW7-2YJvdciGkIGB
Success in encrypting value.
DB_ENCRYPTED_USER_PASSWD_ENV in nnl-install.properties set to the encrypted value.