[
https://issues.apache.org/jira/browse/IMPALA-14898?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18076633#comment-18076633
]
ASF subversion and git services commented on IMPALA-14898:
----------------------------------------------------------
Commit e465a0b0c62e3927c9ed60a6c8c2e674f4626e32 in impala's branch
refs/heads/master from jasonmfehr
[ https://gitbox.apache.org/repos/asf?p=impala.git;h=e465a0b0c ]
IMPALA-14898: Add TLS to External FE Port
Adds TLS to the external fe Thrift server port in the same
manner as other Thrift servers are configured for TLS.
Testing accomplished by enhancing the tests in
test_server_tls.py to open an external fe port and check
that port to ensure it supports the allowed ciphersuites.
Change-Id: I240ebd631a6151bd5adf86231064471fe3d6fcd9
Generated-by: Github Copilot (GPT-5.3-Codex)
Reviewed-on: http://gerrit.cloudera.org:8080/24204
Reviewed-by: Jason Fehr <[email protected]>
Tested-by: Impala Public Jenkins <[email protected]>
> External Frontend Port Does Not Enforce TLS
> -------------------------------------------
>
> Key: IMPALA-14898
> URL: https://issues.apache.org/jira/browse/IMPALA-14898
> Project: IMPALA
> Issue Type: Bug
> Reporter: Jason Fehr
> Assignee: Jason Fehr
> Priority: Critical
>
> The `ThriftServerBuilder` for the external frontend port does not set the TLS
> minimum version or allowed ciphersuites.
> https://github.com/apache/impala/blob/cefeb760a886d28c05f98917cdfeac864728f270/be/src/service/impala-server.cc#L3352-L3367
--
This message was sent by Atlassian Jira
(v8.20.10#820010)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]