[ 
https://issues.apache.org/jira/browse/ZOOKEEPER-5070?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

ASF GitHub Bot updated ZOOKEEPER-5070:
--------------------------------------
    Labels: pull-request-available  (was: )

> Support Single EKU certificates
> -------------------------------
>
>                 Key: ZOOKEEPER-5070
>                 URL: https://issues.apache.org/jira/browse/ZOOKEEPER-5070
>             Project: ZooKeeper
>          Issue Type: Improvement
>          Components: security
>            Reporter: Dávid Paksy
>            Assignee: Dávid Paksy
>            Priority: Major
>              Labels: pull-request-available
>          Time Spent: 10m
>  Remaining Estimate: 0h
>
> h2. Motivation
> ZooKeeper currently only supports dual-purpose certificates. These 
> certificate carry both the serverAuth and clientAuth Extended Key Usages 
> (EKUs), meaning the same key and certificate is used whether the service 
> running on the host is acting as a TLS server or as a client in a mutual-TLS 
> (mTLS) handshake.
> Industry standards and public CA-s (like DigiCert) are sunsetting multi-use 
> certificates, making the current requirement for dual serverAuth and 
> clientAuth EKUs difficult to manage.
>  
> h2. Goal
> Allow configuring a separate client keystore and server truststore so that 
> single-EKU certificates work out of the box, while maintaining full backward 
> compatibility when only the existing keyStore.* properties are set.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to