Aparna Naik created CASSANDRA-21546:
---------------------------------------
Summary: Support pluggable default role initialization (avoid
hardcoded superuser password)
Key: CASSANDRA-21546
URL: https://issues.apache.org/jira/browse/CASSANDRA-21546
Project: Apache Cassandra
Issue Type: Bug
Reporter: Aparna Naik
Assignee: Aparna Naik
Cassandra's first-boot bootstrap hardcodes the creation of a cassandra
superuser role with a default password (cassandra). Every new cluster starts
with this guessable credential exposed until an operator manually rotates or
drops it, and deployments that already use mutual TLS have no way to bootstrap
a superuser identity without also creating this password-based one.
This ticket will make the default role bootstrap pluggable via a new
IDefaultRoleInitializer interface and default_role_initializer config option.
The existing password-based behavior will be the default implementation for
backward compatibility, and it will add a MutualTlsDefaultRoleInitializer that
instead maps a client certificate identity to the superuser role, so no
password credential needs to exist at all.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]