[ 
https://issues.apache.org/jira/browse/NIFI-14858?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18013751#comment-18013751
 ] 

Joe Witt commented on NIFI-14858:
---------------------------------

Jim wrote:

{noformat}
The prescriptive approach to certificate validation favours server-based 
installation and not cloud native deployments with dynamic scaling and 
multiple, often fluid endpoints.
{noformat}

The pushback here is that this fundamental claim doesn't seem to have agreement 
within the context of NiFi's security posture whether on-prem or in the cloud.  
Areas which many of us have a lot of experience.  So let's focus on this part 
and get shared understanding.

> Make SNI checking configurable
> ------------------------------
>
>                 Key: NIFI-14858
>                 URL: https://issues.apache.org/jira/browse/NIFI-14858
>             Project: Apache NiFi
>          Issue Type: Improvement
>    Affects Versions: 2.5.0
>            Reporter: Lars Francke
>            Assignee: Lars Francke
>            Priority: Minor
>          Time Spent: 1.5h
>  Remaining Estimate: 0h
>
> As of NiFi 2.0 SNI certificates are required and the host must match.
> This is a problem for us (and others) when there is for example a load 
> balancer in front which does not match the host name of NiFi.
> Instead of disabling the SNI check by default this makes it configurable.
>  
> I propose introducing two new configuration properties:
>  * nifi.web.https.sni.required (whether a SNI certificate is required)
>  * nifi.web.https.sni.host.check (whether to check the Host from the SNI 
> certificate against the incoming request)



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to