cassandra-commits mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Aleksey Yeschenko (JIRA)" <>
Subject [jira] [Updated] (CASSANDRA-11097) Idle session timeout for secure environments
Date Thu, 04 Jul 2019 16:11:00 GMT


Aleksey Yeschenko updated CASSANDRA-11097:
    Status: Review In Progress  (was: Patch Available)

> Idle session timeout for secure environments
> --------------------------------------------
>                 Key: CASSANDRA-11097
>                 URL:
>             Project: Cassandra
>          Issue Type: Improvement
>          Components: Legacy/CQL
>            Reporter: Jeff Jirsa
>            Assignee: Alex Petrov
>            Priority: Low
>              Labels: lhf, ponies
> A thread on the user list pointed out that some use cases may prefer to have a database
disconnect sessions after some idle timeout. An example would be an administrator who connected
via ssh+cqlsh and then walked away. Disconnecting that user and forcing it to re-authenticate
could protect against unauthorized access.
> It seems like it may be possible to do this using a netty {{IdleStateHandler}} in a way
that's low risk and perhaps off by default.  

This message was sent by Atlassian JIRA

To unsubscribe, e-mail:
For additional commands, e-mail:

View raw message