[RFE] ssl/tls support for cluster and client-server traffic

Bug #1742469 reported by Dmitrii Shcherbakov
16
This bug affects 2 people
Affects Status Importance Assigned to Milestone
OpenStack Percona Cluster Charm
Triaged
Wishlist
Michał Ajduk

Bug Description

Currently there is no support in the charm for enabling TLS for the following use-cases:

1. client-server traffic TLS;
2. server-server traffic TLS.

https://www.percona.com/doc/percona-xtradb-cluster/LATEST/security/encrypt-traffic.html
https://www.percona.com/blog/2017/04/21/simplified-percona-xtradb-cluster-ssl-configuration/

From the usability perspective any client would need to use a CA cert used in this charm as a verifier for a server cert of course which should be an option in the client charm or some other delivery method so this is out of scope for this request.

Tags: cpe-onsite sts
tags: added: cpe-onsite
James Page (james-page)
Changed in charm-percona-cluster:
status: New → Triaged
importance: Undecided → Wishlist
Revision history for this message
Dean Henrichsmeyer (dean) wrote :

Unsubscribing field high.

tags: added: sts
Changed in charm-percona-cluster:
assignee: nobody → Tiago Pasqualini da Silva (tiago.pasqualini)
Changed in charm-percona-cluster:
assignee: Tiago Pasqualini da Silva (tiago.pasqualini) → nobody
Michał Ajduk (majduk)
Changed in charm-percona-cluster:
assignee: nobody → Michał Ajduk (majduk)
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.