gaturchenko opened a new pull request, #2569:
URL: https://github.com/apache/systemds/pull/2569

   This PR adds support for reading in a signed certificate and makes the 
coordinator verify it in place of the existing self-signed certificate 
generation. To that end, the XML config is extended with the following:
   
   | Key                                      | Side        | Comment           
                                                |
   
|------------------------------------------|-------------|--------------------------------------------------------------------|
   | sysds.federated.ssl.cert                 | worker      | X.509 certificate 
chain, PEM, leaf first                           |
   | sysds.federated.ssl.key                  | worker      | matching private 
key, PKCS#8 PEM                                   |
   | sysds.federated.ssl.keyPassword          | worker      | only if the key 
is encrypted                                       |
   | sysds.federated.ssl.trust                | coordinator | certificates 
trusted to sign worker certificates, typically the CA |
   | sysds.federated.ssl.hostnameVerification | coordinator | `true` by default 
                                                 |
   
   Both certificate and key are read by each worker from its own config, so 
they are local per worker. The coordinator has a single trust file, where one 
CA certificate covers any number of workers, and multiple CAs can be 
concatenated into one PEM. With hostname verification on, a worker's 
certificate must be issued for the address the script connects to 
(`san=dns:...`, or `san=ip:...` for IP literals), so a certificate valid for 
one worker cannot be replayed for another.
   
   NB: private keys and certificates are added as a part of this PR for 
SSL-enabled tests to work. They are generated with a dedicated shell script and 
are irrelevant for anything except the tests.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to