Apache Airflow version
3.2.0 (FAB Provider)
What happened?
When running the CLI command airflow users create on a FIPS-enabled system, the command crashes with the following error:
ValueError: [digital envelope routines] unsupported
This happens even if FAB_PASSWORD_HASH_METHOD="pbkdf2:sha256" is explicitly set in webserver_config.py.
Why it happens
In providers/fab/src/airflow/providers/fab/auth_manager/security_manager/override.py, the add_user function calls generate_password_hash(password) without passing the method argument:
https://github.com/apache/airflow/blob/main/providers/fab/src/airflow/providers/fab/auth_manager/security_manager/override.py#L1407
Because the method argument is omitted, it falls back to Werkzeug's default, which is scrypt in Werkzeug >= 3.0.0. scrypt is not a FIPS-approved algorithm, so OpenSSL rejects it and throws the [digital envelope routines] unsupported error.
This completely bypasses the FAB_PASSWORD_HASH_METHOD configuration that was introduced in PR #51858 to fix this exact issue for the Web UI. The Web UI works fine because it uses Flask-AppBuilder's internal views which correctly read the config, but the CLI bypasses this and uses override.py.
This bug also affects add_register_user and reset_password in the same file.
What you think should happen instead?
The add_user, add_register_user, and reset_password methods in override.py should read and respect the FAB_PASSWORD_HASH_METHOD configuration (or fallback to pbkdf2:sha256 for older Werkzeug versions), rather than relying on Werkzeug's hardcoded default.
For example:
hash_method = current_app.config.get("FAB_PASSWORD_HASH_METHOD", "pbkdf2:sha256")
user.password = generate_password_hash(password, method=hash_method)
How to reproduce
- Use a FIPS-enabled OS.
- Ensure Werkzeug >= 3.0.0 is installed.
- Set
FAB_PASSWORD_HASH_METHOD="pbkdf2:sha256" in webserver_config.py.
- Run
airflow users create -r Admin -u admin -e admin@example.com -p admin -f admin -l admin
- Observe the
ValueError: [digital envelope routines] unsupported crash.
Apache Airflow version
3.2.0 (FAB Provider)
What happened?
When running the CLI command
airflow users createon a FIPS-enabled system, the command crashes with the following error:This happens even if
FAB_PASSWORD_HASH_METHOD="pbkdf2:sha256"is explicitly set inwebserver_config.py.Why it happens
In
providers/fab/src/airflow/providers/fab/auth_manager/security_manager/override.py, theadd_userfunction callsgenerate_password_hash(password)without passing themethodargument:https://github.com/apache/airflow/blob/main/providers/fab/src/airflow/providers/fab/auth_manager/security_manager/override.py#L1407
Because the
methodargument is omitted, it falls back to Werkzeug's default, which isscryptin Werkzeug >= 3.0.0.scryptis not a FIPS-approved algorithm, so OpenSSL rejects it and throws the[digital envelope routines] unsupportederror.This completely bypasses the
FAB_PASSWORD_HASH_METHODconfiguration that was introduced in PR #51858 to fix this exact issue for the Web UI. The Web UI works fine because it uses Flask-AppBuilder's internal views which correctly read the config, but the CLI bypasses this and usesoverride.py.This bug also affects
add_register_userandreset_passwordin the same file.What you think should happen instead?
The
add_user,add_register_user, andreset_passwordmethods inoverride.pyshould read and respect theFAB_PASSWORD_HASH_METHODconfiguration (or fallback topbkdf2:sha256for older Werkzeug versions), rather than relying on Werkzeug's hardcoded default.For example:
How to reproduce
FAB_PASSWORD_HASH_METHOD="pbkdf2:sha256"inwebserver_config.py.airflow users create -r Admin -u admin -e admin@example.com -p admin -f admin -l adminValueError: [digital envelope routines] unsupportedcrash.