[
https://issues.apache.org/jira/browse/HDDS-16034?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
ASF GitHub Bot updated HDDS-16034:
----------------------------------
Labels: pull-request-available (was: )
> Certificates omit DNS SANs on clusters with non-public hostname suffixes
> ------------------------------------------------------------------------
>
> Key: HDDS-16034
> URL: https://issues.apache.org/jira/browse/HDDS-16034
> Project: Apache Ozone
> Issue Type: Bug
> Components: Security
> Affects Versions: 2.1.1
> Reporter: Sergey Soldatov
> Assignee: Sergey Soldatov
> Priority: Major
> Labels: pull-request-available
>
> Ozone decides whether a hostname may appear as a dNSName Subject Alternative
> Name by calling commons-validator's DomainValidator, which enforces the IANA
> public TLD list. On clusters whose hosts use an internal suffix or a
> single-label name (scm1.lxd, om.internal, datanode1) that check fails
> everywhere. The CSR and self-signed-certificate builders silently drop every
> DNS SAN and continue, producing IP-only certificates that fail TLS hostname
> verification for by-name connections. The CA's DefaultProfile rejects any CSR
> that does carry such a name, so a node requesting one cannot be certified at
> all, blocking secure bootstrap.
> Suggested fix: replace the public-suffix test with an RFC 1123 hostname
> syntax check in a shared helper, applied symmetrically by both builders and
> by the CA. Internal suffixes and single-label names become legal; malformed,
> wildcard, and IP-literal values stay rejected. No new configuration key and
> no wire change. Certificates on public-suffix clusters are unchanged and need
> no reissue.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]