cassandra-commits mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Jeff Jirsa (JIRA)" <>
Subject [jira] [Commented] (CASSANDRA-13971) Automatic certificate management using Vault
Date Fri, 20 Oct 2017 17:56:00 GMT


Jeff Jirsa commented on CASSANDRA-13971:

Really interesting idea. I need to read more to be sure, but it looks like you're proposing
shipping an API to interact with vault, not actually extending or combining vault into the
project, which would work around any issues with Vault's license (Mozilla license is in [category
b|], which isn't prohibited, but requires
special handling). Is that correct reading of your proposal? 

> Automatic certificate management using Vault
> --------------------------------------------
>                 Key: CASSANDRA-13971
>                 URL:
>             Project: Cassandra
>          Issue Type: Improvement
>          Components: Streaming and Messaging
>            Reporter: Stefan Podkowinski
>            Assignee: Stefan Podkowinski
>             Fix For: 4.x
> We've been adding security features during the last years to enable users to secure their
clusters, if they are willing to use them and do so correctly. Some features are powerful
and easy to work with, such as role based authorization. Other features that require to manage
a local keystore are rather painful to deal with. Think about setting up SSL..
> To be fair, keystore related issues and certificate handling hasn't been invented by
us. We're just following Java standards there. But that doesn't mean that we absolutely have
to, if there are better options. I'd like to give it a shoot and find out if we can automate
certificate/key handling (PKI) by using external APIs. In this case, the implementation will
be based on [Vault|]. But certificate management services offered by
cloud providers may also be able to handle the use-case and I intend to create a generic,
pluggable API for that.

This message was sent by Atlassian JIRA

To unsubscribe, e-mail:
For additional commands, e-mail:

View raw message