Host name verification off is not necessarily bad #28437

This commit is contained in:
Johan Andrén 2020-02-11 14:27:27 +01:00
parent 6120b73918
commit 07e87bc428
3 changed files with 7 additions and 5 deletions

View file

@ -333,6 +333,8 @@ It's recommended that you enable hostname verification with
`akka.remote.artery.ssl.config-ssl-engine.hostname-verification=on`.
When enabled it will verify that the destination hostname matches the hostname in the peer's certificate.
In deployments where hostnames are dynamic and not known up front it can make sense to leave the hostname verification off.
You have a few choices how to set up certificates and hostname verification:
* Have a single set of keys and a single certificate for all nodes and *disable* hostname checking