conduktor.io ↗

KIP-978 — Allow dynamic reloading of certificates with different DN / SANs

Accepted Kafka 3.7 SecurityBroker

Adds a ssl.client.auth.reconfigure.allowed (or equivalent) configuration to permit dynamic TLS certificate reload even when the Subject DN or SANs differ from the previously loaded certificate. Existing KRaft/ZooKeeper dynamic reload validation blocked any DN or SAN change, requiring rolling restarts to rotate certificates or change CAs.

Details

AuthorJakub Scholz
StatusAccepted
Kafka Version3.7
JIRAKAFKA-15464
WikiView on Apache Wiki
Created2023-09-13
Last Modified2023-11-14
Explore how this KIP affects the Kafka protocol in the Protocol Explorer, or see the full KIP database.