Uploaded image for project: 'Cassandra'
  1. Cassandra
  2. CASSANDRA-18034

Adding endpoint verification option to client_encryption_options

    XMLWordPrintableJSON

Details

    • New Feature
    • Status: Resolved
    • Normal
    • Resolution: Fixed
    • 4.1-rc1, 4.1
    • Messaging/Client
    • None

    Description

      Add a new property `client_encryption_options.require_endpoint_verification` in cassandra.yaml to enable endpoint verification on client connections optionally. When this property is set to true, the IP/hostname of the client is verified against the IP/hostname that is present in the SAN of the client certificates. This would help in preventing clients stealing certificates from the hosts and using them while connecting to cassandra.

      Attachments

        Activity

          People

            Jyothsnakonisa Jyothsna Konisa
            Jyothsnakonisa Jyothsna Konisa
            Jyothsna Konisa
            Jon Meredith, Yifan Cai
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Time Tracking

                Estimated:
                Original Estimate - Not Specified
                Not Specified
                Remaining:
                Remaining Estimate - 0h
                0h
                Logged:
                Time Spent - 20m
                20m