Hi,


Cassandra uses standard Java API for SSL security, so in general Java options 
are available.



Best regards, Vladimir Yudovin, 

Winguzone - Cloud Cassandra Hosting






---- On Fri, 09 Jun 2017 10:13:27 -0400 Victor Ashik 
<ash...@microsoft.com.INVALID> wrote ----




Hello,

 

Is it possible to have a CA certificates in truststores, but do any kind of 
certificate pinning, i.e. adding extra requirements for certificates (matching 
hostname or thumbprint) to be trusted by Cassandra for internode and/or client 
communication?

 

The only way to achieve this I was able to find so far is to have only trusted 
certificates in truststores and do not have CA certificates there at all, but 
this will require to change truststores and restart nodes for adding new 
certificates.

 

 

--

Regards,

Victor Ashik







Reply via email to