Commit 7ac57ec
committed
Add note about transport mTLS
Until recently, public CAs would issue certificates with an Extended Key
Usage set that includes the `clientAuth` value, allowing these
certificates to be used for mTLS. Nonetheless it is a mistake to use
such certificates for mTLS. To prevent users from continuing to make
this mistake, all certificates issued by public CAs will soon omit the
`clientAuth` usage value.
Elasticsearch will by default use mTLS for inter-node connections, and
we've recently encountered some users who have been obtaining their
transport certificates from such public CAs and mistakenly using them
for mTLS. This commit adds some documentation clarifying the security
model and giving clearer recommendations in this area.1 parent 02ea910 commit 7ac57ec
File tree
1 file changed
+11
-1
lines changed- docs/reference/elasticsearch/configuration-reference
1 file changed
+11
-1
lines changedLines changed: 11 additions & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1927 | 1927 | | |
1928 | 1928 | | |
1929 | 1929 | | |
1930 | | - | |
| 1930 | + | |
| 1931 | + | |
| 1932 | + | |
| 1933 | + | |
| 1934 | + | |
| 1935 | + | |
| 1936 | + | |
| 1937 | + | |
| 1938 | + | |
| 1939 | + | |
| 1940 | + | |
1931 | 1941 | | |
1932 | 1942 | | |
1933 | 1943 | | |
| |||
0 commit comments