HCD security overview

HCD provides a comprehensive security framework designed for modern enterprise environments. This overview explains the security architecture and key features available in HCD 1.2.

Security architecture

HCD uses a modular security architecture with three main components:

AdvancedAuthenticator

The AdvancedAuthenticator provides flexible authentication support for multiple authentication schemes, enabling gradual migration or hybrid authentication strategies.

  • Internal authentication: Traditional username/password stored in the database

  • LDAP authentication: Integration with Active Directory and other LDAP services

  • OpenID Connect (OIDC): Modern identity provider integration

AdvancedAuthorizer

The AdvancedAuthorizer provides granular access control with:

  • Role-based access control (RBAC): Permissions granted to roles, which are assigned to users

  • Resource hierarchy: Permissions cascade from higher-level resources to lower-level resources

  • Permission inheritance: Roles can inherit permissions from other roles

AdvancedRoleManager

The AdvancedRoleManager handles role assignment and management:

  • Internal role management: Direct mapping of users to roles

  • LDAP role management: Automatic role assignment based on LDAP group membership

  • OIDC role management: Role assignment from JWT claims

Key security features

HCD provides four core security capabilities: authentication, authorization, encryption, and auditing.

Authentication

HCD supports multiple authentication schemes: Internal, LDAP, and OIDC. Multiple schems can be used simultaneously.

Authorization
  • Granular permissions: Control access at keyspace, table, and function levels

  • Role hierarchy: Create complex permission structures with role inheritance

  • Separation of duties: Create administrative roles with limited permissions

Encryption
  • Client-to-node encryption

  • Node-to-node encryption

  • Transparent data encryption (TDE)

  • Key management support

Auditing
  • Comprehensive logging for database activities

  • Filter audit tracking with allowlist and denylist

  • Log to files or database tables

cassandra.yaml configuration

The main security configuration resides in the cassandra.yaml file:

authenticator:
  class_name: com.datastax.cassandra.auth.AdvancedAuthenticator
  parameters:
    enabled: true
    default_scheme: internal
    additional_schemes: oidc, ldap
    plain_text_without_ssl: warn

authorizer:
  class_name: com.datastax.cassandra.auth.AdvancedAuthorizer

role_manager:
  class_name: com.datastax.cassandra.auth.AdvancedRoleManager
  parameters:
    mode: internal

The default configuration is:

  • Authentication: Disabled (authenticator.parameters.enabled: false)

  • Authorization: Disabled (authorizer.parameters.enabled: false)

  • Client-to-node encryption: Disabled (client_encryption_options.enabled: false)

  • Node-to-node encryption: Disabled (server_encryption_options.internode_encryption: none)

  • Transparent data encryption: Disabled (transparent_data_encryption_options.enabled: false)

  • Audit logging: Disabled (audit_logging_options.enabled: false)

Authentication schemes, encryption, and logging require specific settings that are summarized in the following list. For more information, see the documentation for configuring these features.

Internal Authentication

No additional configuration required. Users and passwords are stored in the database.

LDAP Authentication
  • Server configuration (ldap_servers)

  • User search settings (ldap_user_search_filter, ldap_user_search_bases)

  • Group lookup configuration (ldap_group_search_* parameters)

  • Connection settings (ldap_connection_use_tls, ldap_connection_use_ssl)

OIDC Authentication
  • Issuer URL (oidc_issuer)

  • Client configuration (oidc_accepted_audience)

  • JWT claim mapping (oidc_user_name_claim, oidc_user_roles_claims)

  • TLS settings (oidc_use_tls, oidc_truststore_path)

    Client-to-node encryption
    client_encryption_options:
        enabled: true
        keystore: conf/.keystore
        keystore_password: cassandra
        require_client_auth: false
    Node-to-node encryption
    server_encryption_options:
        internode_encryption: all
        keystore: conf/.keystore
        keystore_password: cassandra
        require_client_auth: false
Transparent Data Encryption (TDE)
transparent_data_encryption_options:
    enabled: true
    cipher: AES/CBC/PKCS5Padding
    key_alias: testing:1
    key_provider:
      - class_name: org.apache.cassandra.security.JKSKeyProvider
        parameters:
          - keystore: conf/.keystore
            keystore_password: cassandra
            store_type: JCEKS
Audit logging
audit_logging_options:
    enabled: true
    logger:
      - class_name: BinAuditLogger
    included_categories: QUERY, DML, DDL, AUTH
    excluded_keyspaces: system, system_schema

Authentication changes from HCD 1.x

  • AdvancedAuthenticator replaces the previous HCD Authenticator

  • AdvancedAuthorizer replaces the previous HCD Authorizer

  • Added OIDC support

  • Better support for multiple authentication schemes

  • Better caching and performance optimizations

  • More granular permission controls

  • All authentication settings in cassandra.yaml

Was this helpful?

Give Feedback

How can we improve the documentation?

© Copyright IBM Corporation 2026 | Privacy policy | Terms of use |  Manage Privacy Choices

Apache, Apache Cassandra, Cassandra, Apache Tomcat, Tomcat, Apache Lucene, Apache Solr, Apache Hadoop, Hadoop, Apache Pulsar, Pulsar, Apache Spark, Spark, Apache TinkerPop, TinkerPop, Apache Kafka and Kafka are either registered trademarks or trademarks of the Apache Software Foundation or its subsidiaries in Canada, the United States and/or other countries. Kubernetes is the registered trademark of the Linux Foundation.

General Inquiries: Contact IBM