Configure Solr Basic Authentication¶
Apache Solr stores audit records that Audit Server sends and that Privacera Portal displays. Basic authentication protects Solr with a username and password. When basic authentication is enabled, Privacera services that connect to Solr use the configured credentials automatically.
Note
Solr basic authentication is different from Audit Server authentication. The SOLR_BASIC_AUTH_* variables protect connections to Solr. The AUDITSERVER_AUTH_* variables protect connections to Audit Server.
Enable Solr basic authentication¶
-
Copy the Solr authentication sample file to
config/custom-vars. -
Edit
config/custom-vars/vars.solr.auth.yml.YAML Variable Description SOLR_BASIC_AUTH_ENABLEDSet to trueto require basic authentication for Solr.SOLR_BASIC_AUTH_USERSpecifies the username that Privacera services use to connect to Solr. SOLR_BASIC_AUTH_PASSWORDSpecifies the password that Privacera services use to connect to Solr. -
To avoid storing the password as plain text, store
SOLR_BASIC_AUTH_PASSWORDin Privacera Manager Vault:-
Run the following command:
-
Select the option to edit common Privacera vault secrets.
-
Add the following entry with the same password:
YAML -
Remove or comment out
SOLR_BASIC_AUTH_PASSWORDinconfig/custom-vars/vars.solr.auth.yml.
For more information, see Enable Vault in Privacera Manager.
-
-
Apply the configuration:
Rotate the Solr password¶
Use the following steps to change the Solr password without losing audits. During the rolling upgrade, new audits may be delayed until the Audit Server pods finish restarting.
-
Set the new value for
SOLR_BASIC_AUTH_PASSWORD:- If the password is stored in
config/custom-vars/vars.solr.auth.yml, replace its current value. - If Privacera Manager Vault is enabled, run
./privacera-manager.sh vault, edit the common Privacera vault secrets, and replace the value there. Keep the password removed or commented out invars.solr.auth.yml.
- If the password is stored in
-
Run the Privacera Manager setup and upgrade commands:
Note
While the upgrade is going on, you might see a temporary disturbance in audits. There is no data loss.
The upgrade applies the new password to Solr and redeploys dependent services, including Audit Server. Audit Server gets the new Solr password automatically so it can continue writing audits.
-
Run the post-installation step:
Bash -
Confirm that the Solr and Audit Server pods are running, and then verify that new audits appear in Privacera Portal.
Warning
Do not update only Solr. Audit Server and Privacera Portal must use the same password as Solr. If Audit Server continues to use the old password, it cannot write new audits to Solr. If Privacera Portal continues to use the old password, it cannot read audits from Solr and the audit pages return no records.
- Previous: Setup
- Next: Advanced Configuration