JVM-wide SSL truststore configuration versus DNS TTL tuning for Liquibase remote changelog loading
29.5K reputation · 13 Jan 2023, 16:15 UTC
The goal is to allow Liquibase to retrieve remote changelog files via HTTPS when the server uses a self‑signed certificate and the underlying DNS records change frequently.
Two documented levers exist: adding a custom truststore via the JVM system properties javax.net.ssl.trustStore and javax.net.ssl.trustStorePassword, or reducing the DNS cache TTL with the security property networkaddress.cache.ttl. However, the truststore change is JVM‑wide and may broaden the attack surface if overly permissive CAs are added, while a low TTL raises DNS query volume and can expose the service to DNS‑based attacks.
Which approach offers a better balance of security and operational flexibility for Liquibase? How can the side‑effects on other Java applications be minimized when using a custom truststore? Is there a threshold for networkaddress.cache.ttl that mitigates DNS load without sacrificing responsiveness?