Skip to content

Securing Corosync

Corosync communication must be secured to prevent eavesdropping, tampering, and unauthorized access in a high-availability cluster. This section outlines best practices for encrypting Corosync traffic, implementing authentication, and configuring firewalls to protect cluster node communication.


TLS Encryption for Corosync

Corosync supports Transport Layer Security (TLS) to encrypt node-to-node communication. This prevents sensitive data (e.g., authentication tokens, cluster state) from being intercepted over the network.

1. Generate TLS Certificates

Use OpenSSL to create a Certificate Authority (CA), server certificates, and private keys. Example commands:

# Generate CA key and certificate
openssl genrsa -out ca.key 2048
openssl req -new -x509 -days 365 -key ca.key -out ca.crt

# Generate server key and CSR
openssl genrsa -out node.key 2048
openssl req -new -key node.key -out node.csr

# Sign CSR with CA
openssl x509 -req -in node.csr -CA ca.crt -CAkey ca.key -CAcreateserial -out node.crt -days 365

2. Configure Corosync for TLS

Edit /etc/corosync/corosync.conf to enable TLS:

totem {
    version: 2
    secauth: on
    tls_reject_unencrypted: yes
    tls_certificate: /etc/corosync/node.crt
    tls_key: /etc/corosync/node.key
    tls_ca_certificate: /etc/coros,ync/ca.crt
}
Ensure all nodes share the same CA certificate and use consistent paths for certificates.


Authentication Mechanisms

Corosync uses authentication tokens to verify node identities. Choose a method based on security and compatibility requirements:

Disables authentication entirely. Only use in trusted, isolated networks.

2. md5/sha1 (Legacy, Weak)

Uses pre-shared secret keys. Configure in corosync.conf:

authentication {
    name: sha1
    keyfile: /etc/corosync/auth.key
}
The keyfile must be identical across all nodes and protected with strict permissions (600).

Uses HTTP Basic Auth-style passwords. Create a password file:

htpasswd -c /etc/corosync/cluster.passwd node1
htpasswd /etc/corosync/cluster.passwd node2
Configure corosync.conf:
authentication {
    name: htpasswd
    file: /etc/corosync/cluster.passwd
}
Set file permissions: chmod 600 /etc/corosync/cluster.passwd.


Firewall Configuration

Allow Corosync traffic through the firewall. By default, Corosync uses UDP port 5405. Update your firewall rules accordingly:

Example: iptables

iptables -A INPUT -p udp --dport 5405 -s <node_ip> -j ACCEPT
iptables -A INPUT -p udp --dport 5405 -d <node_ip> -j ACCEPT

Example: firewalld

firewall-cmd --add-rich-rule='rule family="ipv4" source address="<node_ip>" port port=5405 protocol=udp accept' --permanent
firewall-cmd --reload

If TLS is enabled, ensure the firewall allows traffic on the same port (encryption occurs at the transport layer).


Verification and Best Practices

  1. Test Configuration: After changes, run corosync -V to validate syntax and corosync status to check connectivity.
  2. Monitor Logs: Check /var/log/corosync/corosync.log for TLS handshake failures or authentication errors.
  3. Regular Renewals: Rotate TLS certificates and passwords periodically to mitigate long-term key exposure risks.

Key takeaways

  • TLS encryption protects Corosync traffic from eavesdropping by encrypting data in transit.
  • Authentication tokens (e.g., htpasswd) ensure only trusted nodes join the cluster.
  • Firewall rules must allow UDP traffic on port 5405 (or custom port) to enable node communication.
  • Always secure certificate and password files with strict permissions (600) and rotate credentials regularly.