influxdata / influxdata/influxdb-client-go
mTLS Support (Client Certificates)
Nobody has claimed this yet.
- Dominant language
- Go
- Stars
- 653
- Forks
- 120
- Avg merge
- 3m
- Merged PRs (30d)
- 3
Description
Proposal:
Add optional client certificate and key file configuration when connecting to server over TLS. This is required to connect to an InfluxDB 1.13.0+ server which has client certificate authentication (mTLS) enabled.
Link to preview mTLS documentation for InfluxDB server: https://influxdata.github.io/docs-v2/pr-preview/pr-7523/enterprise_influxdb/v1/administration/configure/security/enable_tls/#enable-mutual-tls-mtls
Current behavior:
Current library does not appear to support client certificates.
Desired behavior:
- Library should support configuring optional client certificate and client private key for TLS connections.
- Client certificate and client key configuration are ignored if TLS is not enabled.
- If only the client certificate is configured and no client key is configured, the library should attempt to load the client certificate as a combined certificate / private key file.
- The client should present the certificate to the server if requested by the server.
Alternatives considered:
There is no alternative if the server is configured to require client certificate authentication (mTLS).
Use case:
mTLS is now supported in InfluxDB 1.13.0+. Customers are beginning to require mTLS in their security policies.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by locating the Go client’s TLS connection configuration and its existing TLS-related tests or entry points. Add optional client certificate and key handling, including the combined-file case and TLS-disabled behavior, then verify that the certificate is presented when requested by the server.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- go
- Domain
- authentication, security
- Issue type
- Feature
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 65/100