[ClusterLabs] pcs cluster auth with a key instead of password #179

S Sathish S s.s.sathish at ericsson.com
Mon Aug 17 08:40:34 UTC 2026


Hi Team,

We are running PCS 0.12.2 on RHEL 8 with Pacemaker 3.0.1 and Corosync 3.1.10. Our security compliance framework (CIS Benchmarks, vendor-specific GPRs) requires that all OS accounts have password expiry policies enforced. The hacluster account used by pcs cluster auth currently requires a static password, which conflicts with this requirement.

We are aware of the long-standing feature request pcs#179 (key-based authentication, opened 2018). In March 2022, Tomas Jelinek confirmed it was on the backlog with no ETA.

Our questions:
1. Is there any updated timeline for key-based/certificate-based authentication in PCS 0.12.x ?
2. Are there any alternative mechanisms in PCS 0.12.x to authenticate nodes without relying on the hacluster password (e.g., token-based, certificate mutual TLS)?

Our current workaround is periodic automated password rotation with re-authentication across all cluster nodes, but this introduces operational risk during the rotation window.

Any guidance or roadmap update would be appreciated.

Thanks and Regards,
S Sathish S
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.clusterlabs.org/pipermail/users/attachments/20260817/487f5bff/attachment.htm>


More information about the Users mailing list