Skip to content

RSTUF-CR-25-107: SSL Not Enabled for Broker #709

@kairoaraujo

Description

@kairoaraujo

What do you want to share with us?

SSL/TLS is not enabled for connections to the broker service. Depending on the setup, attack-
ers could intercept connections to the broker and add malicious messages into the stream.
Since the network between the broker and the agents connecting to it should be firewalled and
not accessible to third parties this is considered an informational issue. Nevertheless, using SSL
in these setups would increase security in depth.

References

Security Audit Report

Code of Conduct

  • I agree to follow this project's Code of Conduct

Metadata

Metadata

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions