Solution for clients with long-lived sustained SSL connections using JKS

2018-03-12 Thread Alexander Maniates
Our set up: Brokers on 0.10.1 Clients on 0.9 -On startup, clients are dynamically issued a signed certificate that is vaild for 48 hours. A JKS is created using this certificate. -All brokers have a signed certificate in their JKS that is valid for some years. The issue: Clients only load their

Possible to enable client SSL when PLAINTEXT brokers exist in the cluster?

2018-04-02 Thread Alexander Maniates
Is it possible to enable client SSL when PLAINTEXT brokers exist in the cluster? Suppose you have 9 brokers in a cluster. 8 are configured with both SSL and PLAINTEXT endpoints. One broker is configured with only a PLAINTEXT endpoint, and this broker does NOT OWN any partitions. I supply a list of