KIP-12 — Kafka Sasl/Kerberos and SSL implementation
Accepted Security
Introduces SASL/Kerberos authentication and SSL/TLS encryption to Kafka brokers and clients by defining TransportLayer (PlainTextTransportLayer, SSLTransportLayer) and Authenticator (SaslServerAuthenticator, SaslClientAuthenticator) interfaces layered over the existing NIO channel abstraction. Kafka previously had no authentication or encryption, leaving multi-tenant and internet-facing deployments without wire security.
Details
| Author | Harsha |
| Status | Accepted |
| JIRA | KAFKA-1686 |
| Wiki | View on Apache Wiki |
| Created | 2015-02-09 |
| Last Modified | 2017-09-11 |
Explore how this KIP affects the Kafka protocol in the Protocol Explorer, or see the full KIP database.