Cassandra RBAC and External Identity Providers: Credential Expiration Interoperability
24K reputation · 18 Jul 2023, 03:02 UTC
Implementing a least-privilege security model in Apache Cassandra typically involves configuring the PasswordAuthenticator and utilizing GRANT/REVOKE commands to restrict access to specific keyspaces and tables.
While Cassandra supports granular Role-Based Access Control (RBAC), the internal authentication provider does not natively support automated credential expiration or time-based password rotation. Organizations requiring strict compliance for credential lifecycles often integrate Cassandra with external identity providers via plugins to handle authentication centrally.
There is uncertainty regarding how the internal RBAC system synchronizes with external providers when a credential expires at the identity provider level but the corresponding role permissions remain active within the system_auth keyspace.
- Does the
PasswordAuthenticatorinterface allow for a callback mechanism to trigger the invalidation of internal session tokens upon external credential expiration? - What is the expected behavior for existing active sessions when a user's credentials are revoked or expired in an external LDAP/Kerberos provider?