ppkarwasz opened a new issue, #4350:
URL: https://github.com/apache/logging-log4j2/issues/4350

   ## Description
   
   With `useTls="true"`, the Cassandra appender enables TLS without hostname 
verification,
   and there is no way to turn verification on.
   
   `CassandraManager` only calls `builder.withSSL()`.
   With the Cassandra driver 3.x used by `log4j-cassandra`, the default 
`JdkSSLOptions` validate the certificate chain
   against the JVM trust store, but do not check that the certificate matches 
the host name.
   Unlike the other network appenders, the Cassandra appender accepts no 
`<Ssl>` element
   and ignores `log4j2.sslVerifyHostName`.
   
   Expected behavior:
   
   - enable endpoint identification (e.g. `RemoteEndpointAwareJdkSSLOptions` 
with an `SSLEngine`
     whose `SSLParameters` have `setEndpointIdentificationAlgorithm("HTTPS")`),
     at least when `log4j2.sslVerifyHostName` is `true`, and preferably by 
default;
   - consider accepting an `<Ssl>` element like the other network appenders 
(see #2792).
   
   The documentation of `useTls` (`database.adoc`) is also inconsistent:
   the default column says `true`, while the description says "This is `false` 
by default".
   The builder field defaults to `false`.
   
   ## Configuration
   
   **Version:** 2.26.1 (and `2.x` at `d631e82`)
   
   **Operating system:** any
   
   **JDK:** any
   
   ## Logs
   
   None.
   
   ## Reproduction
   
   Configure a `Cassandra` appender with `useTls="true"` against a node whose 
certificate is trusted by the JVM
   but issued for a different host name: the connection succeeds.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to