Replies: 1 comment 3 replies
-
|
About the reactive datasource because it's based on TCP, mTLS will work. Your question about certificate rotation is interesting. Once the connection is established, it will continue to work until the connection is closed. When a new connection will be established, the rotated certificates should be used. If you see something different, it's most probably a bug. Note that you either need coordinating the certificate upgrades or use a common parent trusted certificate. I honestly have no idea about JDBC. Maybe @yrodiere knows. |
Beta Was this translation helpful? Give feedback.
3 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Hello, I'm looking if it possible to use quarkus with mTLS database connections. My use case is following: postgresql with mTLS auth enabled, certificates provided in PEM format and rotated automatically.
For the JDBC datasource I can see it is supported to set sslmode, but no way to provide client and server certificates/keys. Are there any plans to extend support for these options?
For reactive datasource it seems that mTLS support is present, but it's unclear, what will happen if certificates will be rotated. Will datasource reload them, or it only read them once, and certificate rotation should be handled manually?
Beta Was this translation helpful? Give feedback.
All reactions