KIP-978 — Allow dynamic reloading of certificates with different DN / SANs
Accepted Kafka 3.7 SecurityBroker
Adds a ssl.client.auth.reconfigure.allowed (or equivalent) configuration to permit dynamic TLS certificate reload even when the Subject DN or SANs differ from the previously loaded certificate. Existing KRaft/ZooKeeper dynamic reload validation blocked any DN or SAN change, requiring rolling restarts to rotate certificates or change CAs.
Details
| Author | Jakub Scholz |
| Status | Accepted |
| Kafka Version | 3.7 |
| JIRA | KAFKA-15464 |
| Wiki | View on Apache Wiki |
| Created | 2023-09-13 |
| Last Modified | 2023-11-14 |
Explore how this KIP affects the Kafka protocol in the Protocol Explorer, or see the full KIP database.