You are viewing a plain text version of this content. The canonical link for it is here.
Posted to issues@nifi.apache.org by "Nathan Gough (JIRA)" <ji...@apache.org> on 2018/06/26 16:47:00 UTC

[jira] [Commented] (NIFI-5210) Create service to retrieve TLS configurations from remote endpoint

    [ https://issues.apache.org/jira/browse/NIFI-5210?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16523967#comment-16523967 ] 

Nathan Gough commented on NIFI-5210:
------------------------------------

Would the idea behind having a custom truststore be to separate the NiFi trust from the auto-secure trust? Ie. NiFi won't accept connections with the auto-secure remote server (but the auto-secure will)? The only issue here I see would be a small added complexity for administration. It should also be named obviously (autosecure-truststore).

> Create service to retrieve TLS configurations from remote endpoint
> ------------------------------------------------------------------
>
>                 Key: NIFI-5210
>                 URL: https://issues.apache.org/jira/browse/NIFI-5210
>             Project: Apache NiFi
>          Issue Type: Sub-task
>          Components: Extensions
>    Affects Versions: 1.6.0
>            Reporter: Andy LoPresto
>            Priority: Minor
>              Labels: security, tls
>
> One component of this system will be to retrieve the configurations from a remote service (if the admin opts in). This piece should:
> * communicate over HTTPS only
> ** have a custom truststore?
> * have a configurable URL
> ** have a secondary URL?
> * have a configurable polling interval



--
This message was sent by Atlassian JIRA
(v7.6.3#76005)