ppkarwasz opened a new issue, #4350:
URL: https://github.com/apache/logging-log4j2/issues/4350
## Description
With `useTls="true"`, the Cassandra appender enables TLS without hostname
verification,
and there is no way to turn verification on.
`CassandraManager` only calls `builder.withSSL()`.
With the Cassandra driver 3.x used by `log4j-cassandra`, the default
`JdkSSLOptions` validate the certificate chain
against the JVM trust store, but do not check that the certificate matches
the host name.
Unlike the other network appenders, the Cassandra appender accepts no
`<Ssl>` element
and ignores `log4j2.sslVerifyHostName`.
Expected behavior:
- enable endpoint identification (e.g. `RemoteEndpointAwareJdkSSLOptions`
with an `SSLEngine`
whose `SSLParameters` have `setEndpointIdentificationAlgorithm("HTTPS")`),
at least when `log4j2.sslVerifyHostName` is `true`, and preferably by
default;
- consider accepting an `<Ssl>` element like the other network appenders
(see #2792).
The documentation of `useTls` (`database.adoc`) is also inconsistent:
the default column says `true`, while the description says "This is `false`
by default".
The builder field defaults to `false`.
## Configuration
**Version:** 2.26.1 (and `2.x` at `d631e82`)
**Operating system:** any
**JDK:** any
## Logs
None.
## Reproduction
Configure a `Cassandra` appender with `useTls="true"` against a node whose
certificate is trusted by the JVM
but issued for a different host name: the connection succeeds.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]