[infinispan-issues] [JBoss JIRA] (ISPN-4313) If Hotrod Server encryption's require-ssl-client-auth is set to true, <truststore .. /> existence must be checked

Vijay Bhaskar Chintalapati (JIRA) issues at jboss.org
Thu May 22 17:32:58 EDT 2014


Vijay Bhaskar Chintalapati created ISPN-4313:
------------------------------------------------

             Summary: If Hotrod Server encryption's require-ssl-client-auth is set to true, <truststore .. /> existence must be checked
                 Key: ISPN-4313
                 URL: https://issues.jboss.org/browse/ISPN-4313
             Project: Infinispan
          Issue Type: Bug
          Components: Configuration, Security
    Affects Versions: 7.0.0.Alpha4
            Reporter: Vijay Bhaskar Chintalapati
            Assignee: Dan Berindei
            Priority: Critical


Currently the Infinispan Server can be configured with SSL encryption such that it requires the client to authenticate itself to the server for the purposes of  encryption. This can be done by setting the attribute require-ssl-client-auth="true" as shown below. 

&nbsp;&nbsp;&nbsp;&nbsp;<hotrod-connector socket-binding="hotrod" cache-container="security">
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;....
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<encryption security-realm="ApplicationRealm" require-ssl-client-auth="true"/>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;....
&nbsp;&nbsp;&nbsp;&nbsp;</hotrod>

But when that attribute is set to "true" a check should be enforced to check the existence of the the <truststore .. /> element exists in secruity-realm's <authentication>



--
This message was sent by Atlassian JIRA
(v6.2.3#6260)


More information about the infinispan-issues mailing list