Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Validate CommonName attribute for TLS certificate #2209

Closed
tennix opened this issue Mar 9, 2020 · 1 comment
Closed

Validate CommonName attribute for TLS certificate #2209

tennix opened this issue Mar 9, 2020 · 1 comment
Labels
type/enhancement The issue or PR belongs to an enhancement.

Comments

@tennix
Copy link
Contributor

tennix commented Mar 9, 2020

Feature Request

Describe your feature request related problem:

Currently, any TLS certificates issued by the same CA can access TiDB cluster component. This is insecure as the same CA issued certificates are pretty common.

Describe the feature you'd like:

Allow PD add TLS certificate CN validation, this is the issue in TiKV and TiDB tikv/tikv#6982 pingcap/tidb#15137

Describe alternatives you've considered:

Teachability, Documentation, Adoption, Migration Strategy:

Etcd 3.3.0 supports the same feature https://github.com/etcd-io/etcd/blob/master/Documentation/op-guide/security.md#notes-for-tls-authentication

@tennix tennix added the type/enhancement The issue or PR belongs to an enhancement. label Mar 9, 2020
@tennix tennix changed the title Validate CommonName attribute in TLS certificate Validate CommonName attribute for TLS certificate Mar 9, 2020
@nolouch
Copy link
Contributor

nolouch commented Mar 16, 2020

done

@nolouch nolouch closed this as completed Mar 16, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
type/enhancement The issue or PR belongs to an enhancement.
Projects
None yet
Development

No branches or pull requests

2 participants