rabbitmq-website icon indicating copy to clipboard operation
rabbitmq-website copied to clipboard

Document client TLS properties for HTTP[S]-based peer discovery mechanisms

Open michaelklishin opened this issue 7 years ago • 5 comments
trafficstars

Several peer discovery plugins use HTTP to communicate with their services and there is currently no clear explanation in the docs as to how to configure client TLS options (certificate, private key, verification depth, SNI target and so on) for HTTPS, which leads to questions such as https://github.com/rabbitmq/rabbitmq-peer-discovery-consul/issues/14.

Even before https://github.com/rabbitmq/rabbitmq-peer-discovery-common/issues/6 is addressed a doc example can be provided since it is possible to configure httpc via the advanced.config file.

michaelklishin avatar Aug 09 '18 11:08 michaelklishin

If we use rabbitmq-peer-discovery-k8s, and want to configure the default cipher suites, can this be configured in asvanced.config?

haiyangu avatar Aug 17 '18 01:08 haiyangu

@haiyangu this is not a support forum.

As the issue states, it comes down to Erlang HTTP client (httpc) configuration which supports all the same options as other TLS clients (and servers) in Erlang.

michaelklishin avatar Aug 17 '18 01:08 michaelklishin

it is possible to configure httpc via the advanced.config file

This doesn't appear to be the case, see rabbitmq/rabbitmq-peer-discovery-common#9

lukebakken avatar Apr 24 '19 16:04 lukebakken

This is done for etcd (which no longer is HTTP1.1-based) but we have found out that some code changes may be necessary to make this easy for other mechanisms.

michaelklishin avatar Sep 11 '20 12:09 michaelklishin