Securing Corosync
Corosync communication must be secured to prevent eavesdropping, tampering, and unauthorized access in a high-availability cluster. This section outlines best practices for encrypting Corosync traffic, implementing authentication, and configuring firewalls to protect cluster node communication.
TLS Encryption for Corosync¶
Corosync supports Transport Layer Security (TLS) to encrypt node-to-node communication. This prevents sensitive data (e.g., authentication tokens, cluster state) from being intercepted over the network.
1. Generate TLS Certificates¶
Use OpenSSL to create a Certificate Authority (CA), server certificates, and private keys. Example commands:
# Generate CA key and certificate
openssl genrsa -out ca.key 2048
openssl req -new -x509 -days 365 -key ca.key -out ca.crt
# Generate server key and CSR
openssl genrsa -out node.key 2048
openssl req -new -key node.key -out node.csr
# Sign CSR with CA
openssl x509 -req -in node.csr -CA ca.crt -CAkey ca.key -CAcreateserial -out node.crt -days 365
2. Configure Corosync for TLS¶
Edit /etc/corosync/corosync.conf to enable TLS:
totem {
version: 2
secauth: on
tls_reject_unencrypted: yes
tls_certificate: /etc/corosync/node.crt
tls_key: /etc/corosync/node.key
tls_ca_certificate: /etc/coros,ync/ca.crt
}
Authentication Mechanisms¶
Corosync uses authentication tokens to verify node identities. Choose a method based on security and compatibility requirements:
1. none (Insecure, Not Recommended)¶
Disables authentication entirely. Only use in trusted, isolated networks.
2. md5/sha1 (Legacy, Weak)¶
Uses pre-shared secret keys. Configure in corosync.conf:
600).
3. htpasswd (Recommended)¶
Uses HTTP Basic Auth-style passwords. Create a password file:
Configurecorosync.conf:
Set file permissions: chmod 600 /etc/corosync/cluster.passwd.
Firewall Configuration¶
Allow Corosync traffic through the firewall. By default, Corosync uses UDP port 5405. Update your firewall rules accordingly:
Example: iptables¶
iptables -A INPUT -p udp --dport 5405 -s <node_ip> -j ACCEPT
iptables -A INPUT -p udp --dport 5405 -d <node_ip> -j ACCEPT
Example: firewalld¶
firewall-cmd --add-rich-rule='rule family="ipv4" source address="<node_ip>" port port=5405 protocol=udp accept' --permanent
firewall-cmd --reload
If TLS is enabled, ensure the firewall allows traffic on the same port (encryption occurs at the transport layer).
Verification and Best Practices¶
- Test Configuration: After changes, run
corosync -Vto validate syntax andcorosync statusto check connectivity. - Monitor Logs: Check
/var/log/corosync/corosync.logfor TLS handshake failures or authentication errors. - Regular Renewals: Rotate TLS certificates and passwords periodically to mitigate long-term key exposure risks.
Key takeaways¶
- TLS encryption protects Corosync traffic from eavesdropping by encrypting data in transit.
- Authentication tokens (e.g.,
htpasswd) ensure only trusted nodes join the cluster. - Firewall rules must allow UDP traffic on port 5405 (or custom port) to enable node communication.
- Always secure certificate and password files with strict permissions (
600) and rotate credentials regularly.