Skip to content

Use more clever certificate subject #617

@sbernauer

Description

@sbernauer

Well, currently all certificates get the subject CN=generated certificate for pod.
This imposes real security problems as shown in the code links below.

We should change that, so that one can actually use the subject for authorization. Things that come to my mind:

  1. OPA rules for Kafka using mTLS
  2. NiFi OPA rules and config
  3. @siegfriedweber mentioned the OpenSearch implementation also struggles with our current subject

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions