[ https://issues.apache.org/jira/browse/FLINK-9312?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16469744#comment-16469744 ]
Eron Wright commented on FLINK-9312: ------------------------------------- I believe that this enhancement can be considered as part of [FLIP-26|https://cwiki.apache.org/confluence/pages/viewpage.action?pageId=80453255], with the goal of hardening Flink's intra-cluster communication. [~StephanEwen] do you agree? > Perform mutual authentication during SSL handshakes > --------------------------------------------------- > > Key: FLINK-9312 > URL: https://issues.apache.org/jira/browse/FLINK-9312 > Project: Flink > Issue Type: New Feature > Components: Security > Reporter: Stephan Ewen > Priority: Major > Fix For: 1.6.0 > > > Currently, the Flink processes encrypted connections via SSL: > - Data exchange TM - TM > - RPC JM - TM > - Blob Service JM - TM > However, the server side always accepts any client to build up the > connection, meaning the connections are not strongly authenticated. > Activating SSL mutual authentication solves that - only processes that have > the same certificate can connect. -- This message was sent by Atlassian JIRA (v7.6.3#76005)