Skip to content
This repository has been archived by the owner on Nov 24, 2023. It is now read-only.

Validate CommonName attribute for TLS certificate #524

Closed
tennix opened this issue Mar 9, 2020 · 1 comment
Closed

Validate CommonName attribute for TLS certificate #524

tennix opened this issue Mar 9, 2020 · 1 comment
Assignees
Labels
type/feature-request This issue is a feature request

Comments

@tennix
Copy link
Member

tennix commented Mar 9, 2020

Feature Request

Is your feature request related to a problem? Please describe:

If we follow current TLS in TiDB cluster, any TLS certificates issued by the same CA can access TiDB cluster component. This is insecure as the same CA issued certificates are pretty common.

Describe the feature you'd like:

Allow DM add TLS certificate CN validation, this is the issue in PD, TiKV and TiDB tikv/pd#2209 tikv/tikv#6982 pingcap/tidb#15137

Describe alternatives you've considered:

Teachability, Documentation, Adoption, Migration Strategy:

@WangXiangUSTC
Copy link
Contributor

finish in #569

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
type/feature-request This issue is a feature request
Projects
None yet
Development

No branches or pull requests

2 participants