ppkarwasz commented on issue #2792:
URL: 
https://github.com/apache/logging-log4j2/issues/2792#issuecomment-5727662396

   A private security report received in August 2026 asked us to switch the 
default of `verifyHostName` to `true` in `SslConfiguration` and 
`log4j2.sslVerifyHostName`, which is what this issue proposes. The PMC 
classified the report as hardening rather than a vulnerability, since the 
default is documented and TLS parameters are operator-controlled configuration, 
and a summary will be published on `log4j-user@`.
   
   Two things worth recording here. First, the report points out that an 
operator who configures a restrictive `TrustStore` can easily assume the 
connection is fully verified, so until the default changes we should add a 
warning next to the `verifyHostName` attribute in 
`manual/appenders/network.adoc` and next to the property in 
`manual/systemproperties.adoc`, recommending `true` for every deployment. 
Second, the stalled state of #3902 is the reason the default has not changed 
yet; if the TLS rework takes longer, flipping the default alone, with a 
changelog entry describing the opt-out, is worth doing in a minor release on 
its own.
   
   Reported by @August829
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to