Configure SSL for HCD

Configure SSL for Hyper-Converged Database (HCD) by implementing Client Certificate Authentication. Following this approach, each node verifies the service or client making a request against a local truststore to validate that the certificate was issued by a known Certificate Authority (CA).

  1. Create SSL certificates, keystores, and truststores.

    You can implement SSL using CA signed certificates signed by well-known CAs, or by creating your own root CA. DataStax recommends using certificates signed by a CA to reduce SSL certificate management tasks. However, you can use self-signed certificates with HCD, which supports SSL certificates in local and external keystores.

    Creating your own CA in a production environments typically involves using an intermediary certificate chain, where the root CA signs one or more intermediate certificates with its private key. These intermediary certificates chain together to link back to the root CA, which owns one or more trusted roots.

  2. Encrypt HCD services: Use SSL to encrypt data in node-to-node connections.

  3. Encrypt HCD clients: Use SSL to secure client-to-node connections:

    • Apache Cassandra drivers

    • CQL shell (cqlsh)

    • DataStax Bulk Loader (DSBulk)

    • DataStax Apache Kafka Connector

    • HCD tools

    Connections to clusters through a Mission Control CQL gateway use a gateway Secure Connect Bundle (SCB) that automatically configures SSL for client-to-node connections.

Was this helpful?

Give Feedback

How can we improve the documentation?

© Copyright IBM Corporation 2026 | Privacy policy | Terms of use |  Manage Privacy Choices

Apache, Apache Cassandra, Cassandra, Apache Tomcat, Tomcat, Apache Lucene, Apache Solr, Apache Hadoop, Hadoop, Apache Pulsar, Pulsar, Apache Spark, Spark, Apache TinkerPop, TinkerPop, Apache Kafka and Kafka are either registered trademarks or trademarks of the Apache Software Foundation or its subsidiaries in Canada, the United States and/or other countries. Kubernetes is the registered trademark of the Linux Foundation.

General Inquiries: Contact IBM