feature request: retrieve passwords by rest service

We need Pega to retrieve passwords by rest service where necessary (i.e. oracle,cassandra,… user passwords)

Could you please write a comment if this is right place to ask such a feature? And if it is the right place, is it going to be considered as a feature in future releases?

@ÖzhanA56 please could you clarify your use case a bit further?

Why do you need to retrieve password using APIs? Are you looking for SSO?

What is the security policy in your organization around password storage which warrants this requirement? What is the technical challenge which you are seeing when trying to implement this?

More details will help me determine whether I can approach our technical team for their input.

@MarijeSchillern

At the moment we installed Pega Platform on on-premise openshift clusters. Openshift cluster installation requires pega.yaml file to store (oracle,cassandra service/application users’) passwords in plain format. Our security policy does not allow to store passwords in plain text files. We can meet in zoom and talk if it helps.

@ÖzhanA56 an enhancement request already exists for this requirement.

I have contacted the SME for that area to see if they have any update regarding this FDBK.

@ÖzhanA56

I checked with the SME, and we now support integration with External Secrets.

Please refer to the following:

https://github.com/pegasystems/pega-helm-charts/tree/master/charts/pega#optional-support-for-providing-credentialscertificates-using-external-secrets-operator