influxdata / influxdata/influxdb-client-js
mTLS Support (Client Certificates)
Nobody has claimed this yet.
- Dominant language
- TypeScript
- Stars
- 352
- Forks
- 69
- Avg merge
- 10m
- Merged PRs (30d)
- 11
Description
__Proposal:__
Add optional client certificate and key file configuration when connecting to server over TLS. This is required to connect to an InfluxDB 1.13.0+ server which has client certificate authentication (mTLS) enabled.
Link to preview mTLS documentation for InfluxDB server: https://influxdata.github.io/docs-v2/pr-preview/pr-7523/enterprise_influxdb/v1/administration/configure/security/enable_tls/#enable-mutual-tls-mtls
__Current behavior:__
Current library does not appear to support client certificates.
__Desired behavior:__
- Library should support configuring optional client certificate and client private key for TLS connections.
- Client certificate and client key configuration are ignored if TLS is not enabled.
- If only the client certificate is configured and no client key is configured, the library should attempt to load the client certificate as a combined certificate / private key file.
- The client should present the certificate to the server if requested by the server.
__Alternatives considered:__
There is no alternative if the server is configured to require client certificate authentication (mTLS).
__Use case:__
mTLS is now supported in InfluxDB 1.13.0+. Customers are beginning to require mTLS in their security policies.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
The issue names no files or tests. Start by locating the TLS connection configuration and its client tests in the TypeScript library, then trace how connection options are passed to the server. Done means optional certificate and key settings work for TLS, combined certificate/key files are supported when only the certificate is set, and the settings are ignored without TLS.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- typescript
- Domain
- api, security
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 55/100