WARNING: THIS SITE IS A MIRROR OF GITHUB.COM / IT CANNOT LOGIN OR REGISTER ACCOUNTS / THE CONTENTS ARE PROVIDED AS-IS / THIS SITE ASSUMES NO RESPONSIBILITY FOR ANY DISPLAYED CONTENT OR LINKS / IF YOU FOUND SOMETHING MAY NOT GOOD FOR EVERYONE, CONTACT ADMIN AT ilovescratch@foxmail.com
Skip to content

Use more clever certificate subject #617

@sbernauer

Description

@sbernauer

Well, currently all certificates get the subject CN=generated certificate for pod.
This imposes real security problems as shown in the code links below.

We should change that, so that one can actually use the subject for authorization. Things that come to my mind:

  1. OPA rules for Kafka using mTLS
  2. NiFi OPA rules and config
  3. @siegfriedweber mentioned the OpenSearch implementation also struggles with our current subject

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    Status

    Selected for Development

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions