[ 
https://issues.apache.org/jira/browse/HBASE-30387?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Luca Kovacs updated HBASE-30387:
--------------------------------
    Component/s: security

> Support SingleEKU certificates
> ------------------------------
>
>                 Key: HBASE-30387
>                 URL: https://issues.apache.org/jira/browse/HBASE-30387
>             Project: HBase
>          Issue Type: Improvement
>          Components: security
>            Reporter: Luca Kovacs
>            Assignee: Luca Kovacs
>            Priority: Major
>
> h2. Motivation
> HBase currently only supports dual-purpose certificates. These certificate 
> carry both the serverAuth and clientAuth Extended Key Usages (EKUs), meaning 
> the same key and certificate is used whether the service running on the host 
> is acting as a TLS server or as a client in a mutual-TLS (mTLS) handshake.
> Industry standards and public CA-s (like DigiCert) are sunsetting multi-use 
> certificates, making the current requirement for dual serverAuth and 
> clientAuth EKUs difficult to manage.
> h2. Goal
> Allow configuring a separate client keystore and server truststore so that 
> single-EKU certificates work out of the box, while maintaining full backward 
> compatibility when only the existing properties are set.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to