HCD security overview
HCD provides a comprehensive security framework designed for modern enterprise environments. This overview explains the security architecture and key features available in HCD 2.0.
Security architecture
HCD uses a modular security architecture with three main components:
- AdvancedAuthenticator
-
The AdvancedAuthenticator provides flexible authentication support for multiple authentication schemes, enabling gradual migration or hybrid authentication strategies.
-
Internal authentication: Traditional username/password stored in the database
-
LDAP authentication: Integration with Active Directory and other LDAP services
-
OpenID Connect (OIDC): Modern identity provider integration
-
- AdvancedAuthorizer
-
The AdvancedAuthorizer provides granular access control with:
-
Role-based access control (RBAC): Permissions granted to roles, which are assigned to users
-
Resource hierarchy: Permissions cascade from higher-level resources to lower-level resources
-
Permission inheritance: Roles can inherit permissions from other roles
-
- AdvancedRoleManager
-
The AdvancedRoleManager handles role assignment and management:
-
Internal role management: Direct mapping of users to roles
-
LDAP role management: Automatic role assignment based on LDAP group membership
-
OIDC role management: Role assignment from JWT claims
-
Key security features
HCD provides four core security capabilities: authentication, authorization, encryption, and auditing.
- Authentication
-
HCD supports multiple authentication schemes: Internal, LDAP, and OIDC. Multiple schems can be used simultaneously.
- Authorization
-
-
Granular permissions: Control access at keyspace, table, and function levels
-
Role hierarchy: Create complex permission structures with role inheritance
-
Separation of duties: Create administrative roles with limited permissions
-
- Encryption
-
-
Client-to-node encryption
-
Node-to-node encryption
-
Transparent data encryption (TDE)
-
Key management support
-
- Auditing
-
-
Comprehensive logging for database activities
-
Filter audit tracking with allowlist and denylist
-
Log to files or database tables
-
cassandra.yaml configuration
The main security configuration resides in the cassandra.yaml file:
authenticator:
class_name: com.datastax.cassandra.auth.AdvancedAuthenticator
parameters:
enabled: true
default_scheme: internal
additional_schemes: oidc, ldap
plain_text_without_ssl: warn
authorizer:
class_name: com.datastax.cassandra.auth.AdvancedAuthorizer
role_manager:
class_name: com.datastax.cassandra.auth.AdvancedRoleManager
parameters:
mode: internal
The default configuration is:
-
Authentication: Disabled (
authenticator.parameters.enabled: false) -
Authorization: Disabled (
authorizer.parameters.enabled: false) -
Client-to-node encryption: Disabled (
client_encryption_options.enabled: false) -
Node-to-node encryption: Disabled (
server_encryption_options.internode_encryption: none) -
Transparent data encryption: Disabled (
transparent_data_encryption_options.enabled: false) -
Audit logging: Disabled (
audit_logging_options.enabled: false)
Authentication schemes, encryption, and logging require specific settings that are summarized in the following list. For more information, see the documentation for configuring these features.
- Internal Authentication
-
No additional configuration required. Users and passwords are stored in the database.
- LDAP Authentication
-
-
Server configuration (
ldap_servers) -
User search settings (
ldap_user_search_filter,ldap_user_search_bases) -
Group lookup configuration (
ldap_group_search_*parameters) -
Connection settings (
ldap_connection_use_tls,ldap_connection_use_ssl)
-
- OIDC Authentication
-
-
Issuer URL (
oidc_issuer) -
Client configuration (
oidc_accepted_audience) -
JWT claim mapping (
oidc_user_name_claim,oidc_user_roles_claims) -
TLS settings (
oidc_use_tls,oidc_truststore_path)- Client-to-node encryption
-
client_encryption_options: enabled: true keystore: conf/.keystore keystore_password: cassandra require_client_auth: false - Node-to-node encryption
-
server_encryption_options: internode_encryption: all keystore: conf/.keystore keystore_password: cassandra require_client_auth: false
-
- Transparent Data Encryption (TDE)
-
transparent_data_encryption_options: enabled: true cipher: AES/CBC/PKCS5Padding key_alias: testing:1 key_provider: - class_name: org.apache.cassandra.security.JKSKeyProvider parameters: - keystore: conf/.keystore keystore_password: cassandra store_type: JCEKS - Audit logging
-
audit_logging_options: enabled: true logger: - class_name: BinAuditLogger included_categories: QUERY, DML, DDL, AUTH excluded_keyspaces: system, system_schema
Authentication changes from HCD 1.x
-
AdvancedAuthenticator replaces the previous HCD Authenticator
-
AdvancedAuthorizer replaces the previous HCD Authorizer
-
Added OIDC support
-
Better support for multiple authentication schemes
-
Better caching and performance optimizations
-
More granular permission controls
-
All authentication settings in cassandra.yaml