This repository has been archived by the owner on Nov 24, 2023. It is now read-only.
Validate CommonName attribute for TLS certificate #524
Labels
type/feature-request
This issue is a feature request
Feature Request
Is your feature request related to a problem? Please describe:
If we follow current TLS in TiDB cluster, any TLS certificates issued by the same CA can access TiDB cluster component. This is insecure as the same CA issued certificates are pretty common.
Describe the feature you'd like:
Allow DM add TLS certificate CN validation, this is the issue in PD, TiKV and TiDB tikv/pd#2209 tikv/tikv#6982 pingcap/tidb#15137
Describe alternatives you've considered:
Teachability, Documentation, Adoption, Migration Strategy:
The text was updated successfully, but these errors were encountered: