Skip to content

Use more clever certificate subject #617

@sbernauer

Description

@sbernauer

Well, currently all certificates get the subject CN=generated certificate for pod.
This imposes real security problems as shown in the code links below.

We should change that, so that one can actually use the subject for authorization. Things that come to my mind:

  1. OPA rules for Kafka using mTLS
  2. NiFi OPA rules and config
  3. @siegfriedweber mentioned the OpenSearch implementation also struggles with our current subject

Metadata

Metadata

Type

No type

Projects

Status

Selected for Development

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions