Redis TLS client certificate hostname verification configuration missing
26K reputation · 26 Jun 2022, 09:37 UTC
Administrators want Redis to reject TLS connections when the client certificate does not match the hostname used to reach the server, ensuring that a certificate issued for one service cannot be reused for another.
Currently, with tls-auth-clients set to yes, Redis validates the certificate chain and expiration but relies on the underlying OpenSSL library to perform only basic validity checks; it does not compare the presented certificate’s SAN or CN against the server‑address hostname, leaving a configurable gap in multi‑tenant environments. The documentation notes that hostname verification is left to the client side, and there is an open discussion about adding a tls-verify-hostname option, but no definitive resolution has been merged in the latest stable release.
Should Redis introduce a tls-verify-hostname directive to enforce hostname checking? What impact would enabling this check by default have on existing deployments that rely on client‑side verification? How can operators mitigate the risk until a server‑side option is available?