Skip to content

[Bug] CLI airflow users create ignores FAB_PASSWORD_HASH_METHOD and fails on FIPS systems (Werkzeug 3.0+) #65728

Description

@jotamartos

Apache Airflow version

3.2.0 (FAB Provider)

What happened?

When running the CLI command airflow users create on a FIPS-enabled system, the command crashes with the following error:

ValueError: [digital envelope routines] unsupported

This happens even if FAB_PASSWORD_HASH_METHOD="pbkdf2:sha256" is explicitly set in webserver_config.py.

Why it happens

In providers/fab/src/airflow/providers/fab/auth_manager/security_manager/override.py, the add_user function calls generate_password_hash(password) without passing the method argument:

https://github.com/apache/airflow/blob/main/providers/fab/src/airflow/providers/fab/auth_manager/security_manager/override.py#L1407

Because the method argument is omitted, it falls back to Werkzeug's default, which is scrypt in Werkzeug >= 3.0.0. scrypt is not a FIPS-approved algorithm, so OpenSSL rejects it and throws the [digital envelope routines] unsupported error.

This completely bypasses the FAB_PASSWORD_HASH_METHOD configuration that was introduced in PR #51858 to fix this exact issue for the Web UI. The Web UI works fine because it uses Flask-AppBuilder's internal views which correctly read the config, but the CLI bypasses this and uses override.py.

This bug also affects add_register_user and reset_password in the same file.

What you think should happen instead?

The add_user, add_register_user, and reset_password methods in override.py should read and respect the FAB_PASSWORD_HASH_METHOD configuration (or fallback to pbkdf2:sha256 for older Werkzeug versions), rather than relying on Werkzeug's hardcoded default.

For example:

hash_method = current_app.config.get("FAB_PASSWORD_HASH_METHOD", "pbkdf2:sha256")
user.password = generate_password_hash(password, method=hash_method)

How to reproduce

  1. Use a FIPS-enabled OS.
  2. Ensure Werkzeug >= 3.0.0 is installed.
  3. Set FAB_PASSWORD_HASH_METHOD="pbkdf2:sha256" in webserver_config.py.
  4. Run airflow users create -r Admin -u admin -e admin@example.com -p admin -f admin -l admin
  5. Observe the ValueError: [digital envelope routines] unsupported crash.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions