[
https://issues.apache.org/jira/browse/CASSANDRA-18034?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17634068#comment-17634068
]
Yifan Cai commented on CASSANDRA-18034:
---------------------------------------
Starting commit
CI Results (pending):
||Branch||Source||Circle CI||
|trunk|[branch|https://github.com/yifan_cai/cassandra/tree/commit_remote_branch/CASSANDRA-18034-trunk-86BA8BC6-1F5D-4D57-86C4-95DD19354819]|[build|https://app.circleci.com/pipelines/github/yifan_cai/cassandra?branch=commit_remote_branch%2FCASSANDRA-18034-trunk-86BA8BC6-1F5D-4D57-86C4-95DD19354819]|
> Adding endpoint verification option to client_encryption_options
> ----------------------------------------------------------------
>
> Key: CASSANDRA-18034
> URL: https://issues.apache.org/jira/browse/CASSANDRA-18034
> Project: Cassandra
> Issue Type: New Feature
> Components: Messaging/Client
> Reporter: Jyothsna Konisa
> Assignee: Jyothsna Konisa
> Priority: Normal
> Time Spent: 20m
> Remaining Estimate: 0h
>
> Add a new property `client_encryption_options.require_endpoint_verification`
> in cassandra.yaml to enable endpoint verification on client connections
> optionally. When this property is set to true, the IP/hostname of the client
> is verified against the IP/hostname that is present in the SAN of the client
> certificates. This would help in preventing clients stealing certificates
> from the hosts and using them while connecting to cassandra.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]