Uploaded image for project: 'Apache Cassandra'
  1. Apache Cassandra
  2. CASSANDRA-19669

Audit Log entries are missing identity for mTLS connections

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Normal
    • Resolution: Fixed
    • 5.1
    • Local/Config
    • None

    Description

      Audit log entries are missing the IDENTITY when an mTLS connection is established. Currently, the client state is captured as part of the audit log entries, however the additional metadata for the authenticated user does not get propagated to the entry. For the mTLS connections, this means that the identity information is not included to the log entry details.

      Additionally, when a TLS connection is terminated during handshake (say a client is using an expired certificate) the error is not propagated to the audit log failure attempts.

      Attachments

        1. ci_summary-2.html
          172 kB
          Francisco Guerrero
        2. ci_summary-1.html
          237 kB
          Francisco Guerrero
        3. ci_summary.html
          237 kB
          Francisco Guerrero

        Issue Links

          Activity

            People

              frankgh Francisco Guerrero
              frankgh Francisco Guerrero
              Francisco Guerrero
              Bernardo Botella, Francisco Guerrero
              Votes:
              1 Vote for this issue
              Watchers:
              4 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Time Tracking

                  Estimated:
                  Original Estimate - Not Specified
                  Not Specified
                  Remaining:
                  Remaining Estimate - 0h
                  0h
                  Logged:
                  Time Spent - 3h 20m
                  3h 20m