Uploaded image for project: 'Cassandra'
  1. Cassandra
  2. CASSANDRA-7528

certificate not validated for internode SSL encryption.

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Resolved
    • Normal
    • Resolution: Fixed
    • 2.0.10, 2.1 rc4
    • None
    • None
    • Amazon Linux on various AWS EC2 instance types.

    Description

      An expired certificate may be used to encrypt internode communication.

      To reproduce, set the server_encryption_options to enable internode encryption. Add the private key to the specified .keystore, and an expired certificate generated using the private key to the specified truststore. The same keys are used far all cassandra nodes in the cluster.

      When cassandra is started, it is able to communicate with other cassandra nodes even though the certificate is expired.

      Attachments

        1. 7528.txt
          2 kB
          Brandon Williams

        Activity

          People

            brandon.williams Brandon Williams
            jw.clark Joseph Clark
            Brandon Williams
            Jason Brown
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: