Skip to main content

Enforce encryption

  • October 9, 2018
  • 3 replies
  • 7 views

gjorgjevski

We are running a cluster configured to use SSL for authentication and encryption; i.e., EnableSSL is set to 1 and certificates and keys are in place.

Client authentication is done by usernames and passwords.

With this being said, we would like to enforce that all clients use SSL when connecting. For example, vsql uses it by default, but specifying -m disable lets me connect without any encryption. Is there any way to disallow this? (Likewise for JDBC and ODBC clients.)

3 replies

SruthiA
Forum|alt.badge.img+1
  • Participating Frequently
  • October 9, 2018

Yes, you can disallow by creating client authentication records

created 2 Authentication methods one to reject SSL and other to accept SSL Traffic. Create a role. grant this authentication method to that role and assign all users to newly created role.


gjorgjevski
  • Author
  • New Participant
  • October 15, 2018

Thank you very much! I ended up creating two password-based authentication methods; one for LOCAL, and another one for HOST TLS. This has the implicit effect of not allowing remote connections without TLS/SSL.


SruthiA
Forum|alt.badge.img+1
  • Participating Frequently
  • October 15, 2018

You are welcome.