ppkarwasz commented on issue #2792: URL: https://github.com/apache/logging-log4j2/issues/2792#issuecomment-5727662396
A private security report received in August 2026 asked us to switch the default of `verifyHostName` to `true` in `SslConfiguration` and `log4j2.sslVerifyHostName`, which is what this issue proposes. The PMC classified the report as hardening rather than a vulnerability, since the default is documented and TLS parameters are operator-controlled configuration, and a summary will be published on `log4j-user@`. Two things worth recording here. First, the report points out that an operator who configures a restrictive `TrustStore` can easily assume the connection is fully verified, so until the default changes we should add a warning next to the `verifyHostName` attribute in `manual/appenders/network.adoc` and next to the property in `manual/systemproperties.adoc`, recommending `true` for every deployment. Second, the stalled state of #3902 is the reason the default has not changed yet; if the TLS rework takes longer, flipping the default alone, with a changelog entry describing the opt-out, is worth doing in a minor release on its own. Reported by @August829 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
