| Summary | It was discovered by Elastic engineering that when elasticsearch-certutil CLI tool is used with the csr option in order to create a new Certificate Signing Requests, the associated private key that is generated is stored on disk unencrypted even if the --pass parameter is passed in the command invocation. |
|---|---|
| Publication Date | Aug. 1, 2024, 3:15 a.m. |
| Registration Date | Aug. 1, 2024, 10 a.m. |
| Last Update | Aug. 1, 2024, 9:42 p.m. |