Uploaded image for project: 'Cassandra'
  1. Cassandra
  2. CASSANDRA-13971

Automatic certificate management using Vault

    XMLWordPrintableJSON

Details

    Description

      We've been adding security features during the last years to enable users to secure their clusters, if they are willing to use them and do so correctly. Some features are powerful and easy to work with, such as role based authorization. Other features that require to manage a local keystore are rather painful to deal with. Think about setting up SSL..

      To be fair, keystore related issues and certificate handling hasn't been invented by us. We're just following Java standards there. But that doesn't mean that we absolutely have to, if there are better options. I'd like to give it a shoot and find out if we can automate certificate/key handling (PKI) by using external APIs. In this case, the implementation will be based on Vault. But certificate management services offered by cloud providers may also be able to handle the use-case and I intend to create a generic, pluggable API for that.

      Attachments

        1. start_vault_ssl.sh
          5 kB
          Stefan Podkowinski
        2. patches-13971.tar
          270 kB
          Stefan Podkowinski

        Issue Links

          Activity

            People

              Unassigned Unassigned
              spod Stefan Podkowinski
              Votes:
              0 Vote for this issue
              Watchers:
              16 Start watching this issue

              Dates

                Created:
                Updated:

                Time Tracking

                  Estimated:
                  Original Estimate - Not Specified
                  Not Specified
                  Remaining:
                  Remaining Estimate - 0h
                  0h
                  Logged:
                  Time Spent - 10m
                  10m