gaturchenko opened a new pull request, #2569:
URL: https://github.com/apache/systemds/pull/2569
This PR adds support for reading in a signed certificate and makes the
coordinator verify it in place of the existing self-signed certificate
generation. To that end, the XML config is extended with the following:
| Key | Side | Comment
|
|------------------------------------------|-------------|--------------------------------------------------------------------|
| sysds.federated.ssl.cert | worker | X.509 certificate
chain, PEM, leaf first |
| sysds.federated.ssl.key | worker | matching private
key, PKCS#8 PEM |
| sysds.federated.ssl.keyPassword | worker | only if the key
is encrypted |
| sysds.federated.ssl.trust | coordinator | certificates
trusted to sign worker certificates, typically the CA |
| sysds.federated.ssl.hostnameVerification | coordinator | `true` by default
|
Both certificate and key are read by each worker from its own config, so
they are local per worker. The coordinator has a single trust file, where one
CA certificate covers any number of workers, and multiple CAs can be
concatenated into one PEM. With hostname verification on, a worker's
certificate must be issued for the address the script connects to
(`san=dns:...`, or `san=ip:...` for IP literals), so a certificate valid for
one worker cannot be replayed for another.
NB: private keys and certificates are added as a part of this PR for
SSL-enabled tests to work. They are generated with a dedicated shell script and
are irrelevant for anything except the tests.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]