Host name verification off is not necessarily bad #28437
This commit is contained in:
parent
6120b73918
commit
07e87bc428
3 changed files with 7 additions and 5 deletions
|
|
@ -333,6 +333,8 @@ It's recommended that you enable hostname verification with
|
|||
`akka.remote.artery.ssl.config-ssl-engine.hostname-verification=on`.
|
||||
When enabled it will verify that the destination hostname matches the hostname in the peer's certificate.
|
||||
|
||||
In deployments where hostnames are dynamic and not known up front it can make sense to leave the hostname verification off.
|
||||
|
||||
You have a few choices how to set up certificates and hostname verification:
|
||||
|
||||
* Have a single set of keys and a single certificate for all nodes and *disable* hostname checking
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue