You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Currently, any TLS certificates issued by the same CA can access TiDB cluster component. This is insecure as the same CA issued certificates are pretty common.
Feature Request
Describe your feature request related problem:
Currently, any TLS certificates issued by the same CA can access TiDB cluster component. This is insecure as the same CA issued certificates are pretty common.
Describe the feature you'd like:
Allow PD add TLS certificate CN validation, this is the issue in TiKV and TiDB tikv/tikv#6982 pingcap/tidb#15137
Describe alternatives you've considered:
Teachability, Documentation, Adoption, Migration Strategy:
Etcd 3.3.0 supports the same feature https://github.com/etcd-io/etcd/blob/master/Documentation/op-guide/security.md#notes-for-tls-authentication
The text was updated successfully, but these errors were encountered: