-
Notifications
You must be signed in to change notification settings - Fork 25.6k
Closed
Labels
:Security/SecuritySecurity issues without another labelSecurity issues without another label>bugTeam:SecurityMeta label for security teamMeta label for security team
Description
ES monitors SSL configuration files and hot-reloads them on change. However, instead of monitoring individual files, ES monitors their parent directories. This could be wasteful because it ends up monitoring unnecessary files and directory traversal is in theory unbounded. In addition, hot-reload works only for files specified in the YAML configuration, i.e. you need to change an existing file for reload to happen, simply adding a new file does not work.
We should fix it by monitoring individual files. As an example, the SSL reloading for reindexing is already monitoring individual files.
DaveCTurner
Metadata
Metadata
Assignees
Labels
:Security/SecuritySecurity issues without another labelSecurity issues without another label>bugTeam:SecurityMeta label for security teamMeta label for security team