Coder Social home page Coder Social logo

Comments (3)

ryanuber avatar ryanuber commented on June 15, 2024

The main problem with this is that it introduces a potential security hole, where a member receives a new key over an un-encrypted gossip channel. The key transmitted in clear text would allow any MITM to obtain full access to the cluster simply by observing the key and joining. In order to talk to any member in the cluster, a member must possess a valid primary encryption key. Memberlist purposely does not act on messages received which are not decipherable with any key in the ring to protect against this. There is probably room for a better secure introduction flow, but it is likely more complicated to do it correctly.

from memberlist.

jsternberg avatar jsternberg commented on June 15, 2024

What about if additional keys could be introduced from some bootstrapping mechanism like the config file? You would also likely need to mark which messages had been decrypted so you avoid accidentally installing an unencrypted key into the cluster. The main problem is that initially bootstrapping encryption requires taking the server offline at the moment. Is there any way to do a rolling restart while enabling encryption on the cluster?

Would you guys be open to a patch that attempts to implement this functionality?

from memberlist.

rboyer avatar rboyer commented on June 15, 2024

@jsternberg I submitted a consul PR that has a variation of this implemented: hashicorp/consul#2141

from memberlist.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.