conduktor.io ↗

KIP-12 — Kafka Sasl/Kerberos and SSL implementation

Accepted Security

Introduces SASL/Kerberos authentication and SSL/TLS encryption to Kafka brokers and clients by defining TransportLayer (PlainTextTransportLayer, SSLTransportLayer) and Authenticator (SaslServerAuthenticator, SaslClientAuthenticator) interfaces layered over the existing NIO channel abstraction. Kafka previously had no authentication or encryption, leaving multi-tenant and internet-facing deployments without wire security.

Details

AuthorHarsha
StatusAccepted
JIRAKAFKA-1686
WikiView on Apache Wiki
Created2015-02-09
Last Modified2017-09-11
Explore how this KIP affects the Kafka protocol in the Protocol Explorer, or see the full KIP database.