<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>idea Support custom credential provider for AWS S3 endpoint in Suggest an Idea</title>
    <link>https://community.qlik.com/t5/Suggest-an-Idea/Support-custom-credential-provider-for-AWS-S3-endpoint/idi-p/1780369</link>
    <description>&lt;P&gt;I would like to propose and enhancement to the AWS S3 endpoint to support custom credential providers.&lt;/P&gt;&lt;P&gt;Currently the S3 endpoint support static long living key pair option, EC2 IAM role option or a STS based option.&lt;/P&gt;&lt;P&gt;All of these options are not part of the security best practices at our enterprise.&lt;/P&gt;&lt;P&gt;We use Hashicorp Vault to provision temporary, short lived AWS credentials. The AWS S3 endpoint should fetching these temporary credentials from valut and should also support refreshing the credentials seamlessly. The temporary credentials have a session token along with the access key and secret key.&lt;/P&gt;</description>
    <pubDate>Thu, 04 Feb 2021 23:38:52 GMT</pubDate>
    <dc:creator>Prabodh</dc:creator>
    <dc:date>2021-02-04T23:38:52Z</dc:date>
    <item>
      <title>Re: Support custom credential provider for AWS S3 endpoint - Status changed to: Open - Collecting Feedback</title>
      <link>https://community.qlik.com/t5/Suggest-an-Idea/Support-custom-credential-provider-for-AWS-S3-endpoint/idc-p/1780879#M4941</link>
      <description>&lt;P&gt;Thank you for the suggestion.&amp;nbsp; We would like to collect feedback from others on direct integration with Hashicorp Vault.&lt;/P&gt;&lt;P&gt;We do provide a method for integration with external credentials, though it is not optimized for short-lived credentials:&amp;nbsp;&lt;A href="https://help.qlik.com/en-US/replicate/November2020/Content/Replicate/Main/Security/external_credentials.htm" target="_blank"&gt;https://help.qlik.com/en-US/replicate/November2020/Content/Replicate/Main/Security/external_credentials.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Feb 2021 14:00:42 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Suggest-an-Idea/Support-custom-credential-provider-for-AWS-S3-endpoint/idc-p/1780879#M4941</guid>
      <dc:creator>Shelley_Brennan</dc:creator>
      <dc:date>2021-02-08T14:00:42Z</dc:date>
    </item>
    <item>
      <title>Re: Support custom credential provider for AWS S3 endpoint</title>
      <link>https://community.qlik.com/t5/Suggest-an-Idea/Support-custom-credential-provider-for-AWS-S3-endpoint/idc-p/1783079#M5103</link>
      <description>&lt;P&gt;Hi Shelley,&lt;/P&gt;&lt;P&gt;The credential addon will not work for us as it would still require provisioning long-living AWS secret key and access key pair - which is against our security best practices.&lt;/P&gt;&lt;P&gt;We need the ability to integrate a c&lt;FONT size="3"&gt;ustom credential provider for AWS. Check "Specifying a Credential Provider or Provider Chain" and "E&lt;/FONT&gt;&lt;FONT size="3"&gt;xplicitly Specifying Credentials&lt;/FONT&gt;&lt;FONT size="3"&gt;" sections in this &lt;A href="https://docs.aws.amazon.com/sdk-for-java/v1/developer-guide/credentials.html" target="_blank" rel="noopener"&gt;AWS documentation&lt;/A&gt;. Note: I am providing Java sdk example as it is the best documented.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="3"&gt;In our case, we would need the ability to return something similar to &lt;A href="https://docs.aws.amazon.com/AWSJavaSDK/latest/javadoc/index.html?com/amazonaws/auth/BasicSessionCredentials.html" target="_self"&gt;BasicSessionCredentials&lt;/A&gt;&amp;nbsp;and expect Replicate to understand it and refresh it once the credentials are nearing expiry. The interface exposed by Replicate would look something similar to &lt;A href="https://docs.aws.amazon.com/AWSJavaSDK/latest/javadoc/index.html?com/amazonaws/auth/AWSCredentials.html" target="_blank" rel="noopener"&gt;AWSRefreshableSessionCredentials&lt;/A&gt;.&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Feb 2021 15:18:36 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Suggest-an-Idea/Support-custom-credential-provider-for-AWS-S3-endpoint/idc-p/1783079#M5103</guid>
      <dc:creator>Prabodh</dc:creator>
      <dc:date>2021-02-16T15:18:36Z</dc:date>
    </item>
    <item>
      <title>From now on, please track this idea from the Ideation por...</title>
      <link>https://community.qlik.com/t5/Suggest-an-Idea/Support-custom-credential-provider-for-AWS-S3-endpoint/idc-p/2101533#M14772</link>
      <description>&lt;P&gt;From now on, please track this idea from the Ideation portal.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;A title="Link to new idea" href="https://ideation.qlik.com/app/#/case/274780" target="_blank" rel="noopener"&gt;Link to new idea&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Meghann&lt;/P&gt;&lt;P data-unlink="true"&gt;&lt;EM&gt;NOTE: Upon clicking this link 2 tabs may open - please feel free to close the one with a login page. If you &lt;STRONG&gt;only&lt;/STRONG&gt; see 1 tab with the login page, please try clicking this link first: &lt;STRONG&gt;&lt;A title="Authenticate me!" href="#" target="_blank" rel="noopener"&gt;Authenticate me!&lt;/A&gt;&lt;/STRONG&gt;&amp;nbsp;t&lt;/EM&gt;&lt;EM&gt;hen try the link above again. Ensure pop-up blocker is off.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Aug 2023 16:33:40 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Suggest-an-Idea/Support-custom-credential-provider-for-AWS-S3-endpoint/idc-p/2101533#M14772</guid>
      <dc:creator>Meghann_MacDonald</dc:creator>
      <dc:date>2023-08-02T16:33:40Z</dc:date>
    </item>
    <item>
      <title>Re: Support custom credential provider for AWS S3 endpoint - Status changed to: Closed - Archived</title>
      <link>https://community.qlik.com/t5/Suggest-an-Idea/Support-custom-credential-provider-for-AWS-S3-endpoint/idc-p/2101534#M14773</link>
      <description />
      <pubDate>Wed, 02 Aug 2023 16:33:42 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Suggest-an-Idea/Support-custom-credential-provider-for-AWS-S3-endpoint/idc-p/2101534#M14773</guid>
      <dc:creator>Ideation</dc:creator>
      <dc:date>2023-08-02T16:33:42Z</dc:date>
    </item>
  </channel>
</rss>

