Go to file
Francisco Guerrero a0af41f666 CASSANDRA-18951: Add option for MutualTlsAuthenticator to restrict the certificate validity period
In this commit, we introduce two new optional options for the `server_encryption_options`
and the `client_encryption_options`. The options are `max_certificate_validity_period` and
`certificate_validity_warn_threshold`. Both options can be configured as a duration
configuration parameter as defined by the `DurationSpec` (see CASSANDRA-15234). The resolution
for these new properties is minutes.

When specified, the certificate validation implementation will take that information
and reject certificates that are older than the maximum allowed certificate validity period,
translating into a rejection from the authenticating user.

The `certificate_validity_warn_threshold` option can be configured to emit warnings (log entries)
when the certificate exceeds the validity threshold.

patch by Francisco Guerrero; reviewed by Andy Tolbert, Abe Ratnofsky, Dinesh Joshi for CASSANDRA-18951
2024-03-25 16:58:36 -07:00
.build Merge branch 'cassandra-5.0' into trunk 2024-03-22 16:51:23 -04:00
.circleci Merge branch 'cassandra-5.0' into trunk 2024-03-20 08:08:39 +01:00
.github Add pull request template and modify README to include Jira and mailing list link 2022-09-21 09:10:28 +02:00
.jenkins Add an optimized default configuration to tests and make it available for new users 2024-03-07 11:08:44 +02:00
bin Merge branch 'cassandra-5.0' into trunk 2024-03-19 23:48:48 -05:00
ci Implementation of Transactional Cluster Metadata as described in CEP-21 2023-11-24 10:26:08 +00:00
conf CASSANDRA-18951: Add option for MutualTlsAuthenticator to restrict the certificate validity period 2024-03-25 16:58:36 -07:00
debian Merge branch 'cassandra-5.0' into trunk 2024-02-08 06:14:07 -06:00
doc Add LIST SUPERUSERS CQL statement 2024-03-13 12:52:46 +01:00
examples Set right client auth for creating SSL context in mTLS optional mode 2023-12-19 13:54:28 -07:00
ide Remove dependency on Sigar in favor of OSHI 2024-01-23 11:54:20 +01:00
lib Upgrade Python driver to 3.29.0 2024-01-19 17:14:57 +00:00
pylib Merge branch 'cassandra-5.0' into trunk 2024-03-19 23:48:48 -05:00
redhat Merge branch 'cassandra-5.0' into trunk 2024-02-08 06:14:07 -06:00
src CASSANDRA-18951: Add option for MutualTlsAuthenticator to restrict the certificate validity period 2024-03-25 16:58:36 -07:00
test CASSANDRA-18951: Add option for MutualTlsAuthenticator to restrict the certificate validity period 2024-03-25 16:58:36 -07:00
tools Avoid exposing intermediate state while replaying log during startup 2024-03-08 12:52:42 +01:00
.asf.yaml Notify the corresponding JIRA issue as soon as the PR is raised 2023-03-29 06:24:34 -05:00
.gitignore Implementation of Transactional Cluster Metadata as described in CEP-21 2023-11-24 10:26:08 +00:00
CASSANDRA-14092.txt Default to nb instead of nc for sstable formats 2023-11-13 09:26:11 +01:00
CHANGES.txt Merge branch 'cassandra-5.0' into trunk 2024-03-25 14:25:59 +01:00
CONTRIBUTING.md Merge branch 'cassandra-3.11' into trunk 2021-04-22 08:32:58 -05:00
LICENSE.txt Merge branch 'cassandra-3.11' into cassandra-4.0 2023-08-31 22:39:56 +02:00
NEWS.txt Merge branch 'cassandra-5.0' into trunk 2024-03-19 23:48:48 -05:00
NOTICE.txt Merge branch 'cassandra-3.11' into cassandra-4.0 2023-02-22 10:25:08 -06:00
README.asc Update version in readme 2024-03-01 08:36:40 -05:00
TESTING.md Improve and clean up documentation and fix typos 2023-01-26 14:42:47 +01:00
build-shaded-dtest-jar.sh Merge branch 'cassandra-3.11' into trunk 2021-04-19 17:39:10 +02:00
build.properties.default Missing license info and headers 2023-08-31 22:30:42 +02:00
build.xml Merge branch 'cassandra-5.0' into trunk 2024-03-07 13:19:16 +02:00
relocate-dependencies.pom Merge branch 'cassandra-3.11' into cassandra-4.0 2023-05-31 12:04:29 -06:00

README.asc

Apache Cassandra
-----------------

Apache Cassandra is a highly-scalable partitioned row store. Rows are organized into tables with a required primary key.

https://cwiki.apache.org/confluence/display/CASSANDRA2/Partitioners[Partitioning] means that Cassandra can distribute your data across multiple machines in an application-transparent matter. Cassandra will automatically repartition as machines are added and removed from the cluster.

https://cwiki.apache.org/confluence/display/CASSANDRA2/DataModel[Row store] means that like relational databases, Cassandra organizes data by rows and columns. The Cassandra Query Language (CQL) is a close relative of SQL.

For more information, see http://cassandra.apache.org/[the Apache Cassandra web site].

Issues should be reported on https://issues.apache.org/jira/projects/CASSANDRA/issues/[The Cassandra Jira].

Requirements
------------
- Java: see supported versions in build.xml (search for property "java.supported").
- Python: for `cqlsh`, see `bin/cqlsh` (search for function "is_supported_version").


Getting started
---------------

This short guide will walk you through getting a basic one node cluster up
and running, and demonstrate some simple reads and writes. For a more-complete guide, please see the Apache Cassandra website's https://cassandra.apache.org/doc/latest/cassandra/getting_started/index.html[Getting Started Guide].

First, we'll unpack our archive:

  $ tar -zxvf apache-cassandra-$VERSION.tar.gz
  $ cd apache-cassandra-$VERSION

After that we start the server. Running the startup script with the -f argument will cause
Cassandra to remain in the foreground and log to standard out; it can be stopped with ctrl-C.

  $ bin/cassandra -f

Now let's try to read and write some data using the Cassandra Query Language:

  $ bin/cqlsh

The command line client is interactive so if everything worked you should
be sitting in front of a prompt:

----
Connected to Test Cluster at localhost:9160.
[cqlsh 6.3.0 | Cassandra 5.0-SNAPSHOT | CQL spec 3.4.7 | Native protocol v5]
Use HELP for help.
cqlsh>
----

As the banner says, you can use 'help;' or '?' to see what CQL has to
offer, and 'quit;' or 'exit;' when you've had enough fun. But lets try
something slightly more interesting:

----
cqlsh> CREATE KEYSPACE schema1
       WITH replication = { 'class' : 'SimpleStrategy', 'replication_factor' : 1 };
cqlsh> USE schema1;
cqlsh:Schema1> CREATE TABLE users (
                 user_id varchar PRIMARY KEY,
                 first varchar,
                 last varchar,
                 age int
               );
cqlsh:Schema1> INSERT INTO users (user_id, first, last, age)
               VALUES ('jsmith', 'John', 'Smith', 42);
cqlsh:Schema1> SELECT * FROM users;
 user_id | age | first | last
---------+-----+-------+-------
  jsmith |  42 |  john | smith
cqlsh:Schema1>
----

If your session looks similar to what's above, congrats, your single node
cluster is operational!

For more on what commands are supported by CQL, see
http://cassandra.apache.org/doc/latest/cql/[the CQL reference]. A
reasonable way to think of it is as, "SQL minus joins and subqueries, plus collections."

Wondering where to go from here?

  * Join us in #cassandra on the https://s.apache.org/slack-invite[ASF Slack] and ask questions.
  * Subscribe to the Users mailing list by sending a mail to
    user-subscribe@cassandra.apache.org.
  * Subscribe to the Developer mailing list by sending a mail to
    dev-subscribe@cassandra.apache.org.
  * Visit the http://cassandra.apache.org/community/[community section] of the Cassandra website for more information on getting involved.
  * Visit the http://cassandra.apache.org/doc/latest/development/index.html[development section] of the Cassandra website for more information on how to contribute.