# Rancher security documentation

**URL:** <https://forums.suse.com/t/rancher-security-documentation/168>\
**Category:** Rancher 1.x\
**Created:** [July 28, 2015, 1:57pm UTC](https://forums.suse.com/t/rancher-security-documentation/168 "2015-07-28T13:57:10Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![tobowers](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/tobowers/32/22_2.png) [@tobowers](https://forums.suse.com/u/tobowers)\
**Post date:** [July 28, 2015, 1:57pm UTC](https://forums.suse.com/t/rancher-security-documentation/168/1 "2015-07-28T13:57:10Z")

</div>

Hey guys!

Is there any documentation (or even a part of the code I could look at) that talks about how rancher handles security? Specifically I’m interested in how the rancher agents know to trust the server and how the ipsec password is transferred and stored.

Thanks!

Topper

---

<div class="post-metadata">

**Author:** ![tobowers](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/tobowers/32/22_2.png) [@tobowers](https://forums.suse.com/u/tobowers)\
**Post date:** [July 28, 2015, 1:57pm UTC](https://forums.suse.com/t/rancher-security-documentation/168/2 "2015-07-28T13:57:39Z")

</div>

Is there an ipsec password pair per host combination or is it a cluster wide pw?

---

<div class="post-metadata">

**Author:** ![vincent](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vincent/32/7156_2.png) [@vincent](https://forums.suse.com/u/vincent)\
**Post date:** [July 28, 2015, 3:29pm UTC](https://forums.suse.com/t/rancher-security-documentation/168/3 "2015-07-28T15:29:29Z")

</div>

The registration token (long URL in Add Host -\> Custom) is used by the agent to connect to the server for the first time and generate an agent account and API key pair. That key pair is then used for all subsequent communication using the same authentication and authorization logic as there is for other kinds of accounts, like environment API keys.

The design is that the agent is untrusted because it is running on outside and potentially hostile (to the server) hardware. So the agent accounts have access to only the resources they need in the API, replies to events are checked that the event was actually sent to that agent, etc. There is not as much in the opposite direction for the agent to verify the host. You’d want to setup TLS (which should work now in 0.30 without those buffer settings 😄) and the cert will be verified. We plan on making this easier to setup as more of a managed solution option (vs configuring nginx on the side on your own).

The IPSec key is per-environment (the UI term, the drop down in the upper right) generated on the server, stored in the database, and sent to the host as part of the agent registration with the API key pair. The connections are point to point between hosts and AES encrypted, which is accelerated by most modern CPUs and can do at least a couple gbps

---

<div class="post-metadata">

**Author:** ![vincent](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vincent/32/7156_2.png) [@vincent](https://forums.suse.com/u/vincent)\
**Post date:** [July 28, 2015, 3:35pm UTC](https://forums.suse.com/t/rancher-security-documentation/168/4 "2015-07-28T15:35:50Z")

</div>

@denise I think a documentation section is in order for stuff like this.

---

<div class="post-metadata">

**Author:** ![tobowers](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/tobowers/32/22_2.png) [@tobowers](https://forums.suse.com/u/tobowers)\
**Post date:** [July 29, 2015, 12:55am UTC](https://forums.suse.com/t/rancher-security-documentation/168/5 "2015-07-29T00:55:54Z")

</div>

Thanks for this!

Is the IPsec key ever stored on disk or is it just in memory (on the agent)?

Possible to use SSL RDS connections for the mysql database? [https://aws.amazon.com/blogs/aws/amazon-rds-support-for-ssl-connections/](https://aws.amazon.com/blogs/aws/amazon-rds-support-for-ssl-connections/)
