Class MutualTlsInternodeAuthenticator

java.lang.Object
org.apache.cassandra.auth.MutualTlsInternodeAuthenticator
All Implemented Interfaces:
IInternodeAuthenticator

public class MutualTlsInternodeAuthenticator extends Object implements IInternodeAuthenticator
  • Constructor Details

    • MutualTlsInternodeAuthenticator

      public MutualTlsInternodeAuthenticator(Map<String,String> parameters)
  • Method Details

    • authenticate

      public boolean authenticate(InetAddress remoteAddress, int remotePort)
      Description copied from interface: IInternodeAuthenticator
      Decides whether or not a peer is allowed to connect to this node. If this method returns false, the socket will be immediately closed.
      Specified by:
      authenticate in interface IInternodeAuthenticator
      Parameters:
      remoteAddress - ip address of the connecting node.
      remotePort - port of the connecting node.
      Returns:
      true if the connection should be accepted, false otherwise.
    • authenticate

      public boolean authenticate(InetAddress remoteAddress, int remotePort, Certificate[] certificates, IInternodeAuthenticator.InternodeConnectionDirection connectionType)
      Description copied from interface: IInternodeAuthenticator
      Decides whether a peer is allowed to connect to this node. If this method returns false, the socket will be immediately closed.

      Default implementation calls authenticate method by IP and port method

      1. If it is IP based authentication ignore the certificates & connectionType parameters in the implementation of this method. 2. For certificate based authentication like mTLS, server's identity for outbound connections is verified by the trusted root certificates in the outbound_keystore. In such cases this method may be overridden to return true when certificateType is OUTBOUND, as the authentication of the server happens during SSL Handshake.

      Specified by:
      authenticate in interface IInternodeAuthenticator
      Parameters:
      remoteAddress - ip address of the connecting node.
      remotePort - port of the connecting node.
      certificates - peer certificates
      connectionType - If the connection is inbound/outbound connection.
      Returns:
      true if the connection should be accepted, false otherwise.
    • validateConfiguration

      public void validateConfiguration() throws ConfigurationException
      Description copied from interface: IInternodeAuthenticator
      Validates configuration of IInternodeAuthenticator implementation (if configurable).
      Specified by:
      validateConfiguration in interface IInternodeAuthenticator
      Throws:
      ConfigurationException - when there is a configuration error.
    • authenticateInternodeWithMtls

      protected boolean authenticateInternodeWithMtls(InetAddress remoteAddress, int remotePort, Certificate[] certificates, IInternodeAuthenticator.InternodeConnectionDirection connectionType)