Authentication
Secure your Cassandra cluster - Control who can access your data!
🔍 What is Authentication?
Authentication verifies WHO you are - like checking your ID at the door!
The Problem Without Authentication:
With Authentication Enabled:
What Authentication Protects:
- 🔒 CQL Access: Who can connect via cqlsh or drivers
- 🔧 Nodetool Access: Who can run admin commands
- 📊 JMX Access: Who can monitor cluster metrics
- 🔐 Internal Communication: Node-to-node authentication
Default = Insecure!
Cassandra ships with authentication DISABLED by default!
This means anyone who can reach your cluster can connect and do ANYTHING. Always enable authentication in production!
⚖️ Authentication vs Authorization
Two different concepts - both essential!
Authentication
"WHO are you?"
Purpose:
- Verify identity
- Check username/password
- Allow or deny connection
Example:
Authorization
"WHAT can you do?"
Purpose:
- Check permissions
- Control access to data
- Allow or deny operations
Example:
The Complete Security Flow
🛠️ Cassandra Authenticators
Choose how to authenticate!
AllowAllAuthenticator (Default)
⚠️ INSECURE - Anyone can connect
PasswordAuthenticator
✅ RECOMMENDED - Built-in secure authentication
Custom Authenticator (LDAP/Kerberos)
Enterprise authentication integration
⚡ Enabling Authentication - Complete Guide
Step-by-step with all commands!
Before You Start - Critical!
- ⚠️ Take snapshot backup before enabling auth
- ⚠️ Enable on ALL nodes in rolling fashion
- ⚠️ Test in dev first - don't experiment in production
- ⚠️ Update applications with credentials before enabling
- ⚠️ Have console access in case you get locked out
Step-by-Step Enablement Process
Step 1: Configure system_auth Keyspace
Step 2: Edit cassandra.yaml on First Node
Step 3: Restart First Node
Step 4: Change Default Superuser Password
Step 5: Rolling Restart Other Nodes
Step 6: Update Applications
👥 User Management
Create and manage users!
Creating Users (Roles)
Listing Users
Modifying Users
Deleting Users
Password Policies
Strong Password Guidelines
- ✅ Minimum 12 characters
- ✅ Mix: Uppercase, lowercase, numbers, symbols
- ✅ Unique per user - no shared passwords
- ✅ Rotate regularly - change every 90 days
- ❌ Avoid: Dictionary words, personal info, sequences
- 🔐 Store securely: Use password manager or secrets management
💼 Real-World Scenarios
Complete authentication setups!
Scenario 1: Enabling Authentication on Production Cluster
Scenario 2: Multi-Tenant Application Setup
Scenario 3: Emergency - Locked Out of Cluster
🔧 Troubleshooting Authentication Issues
Fix common problems!
❌ "Unable to connect: Authentication required"
❌ "Provided username/password are incorrect"
❌ system_auth Unavailable After Restart
❌ Application Can't Connect After Enabling Auth
💡 Best Practices
Security done right!
DO
- Enable auth in production
- Set system_auth RF >= 3
- Change default password immediately
- Use strong passwords (12+ chars)
- Create separate users per app/team
- Maintain multiple superusers
- Rotate passwords regularly (90 days)
- Use least privilege principle
- Test in dev before production
- Store credentials securely
DON'T
- Leave AllowAll in production
- Use default cassandra/cassandra
- Share passwords between users
- Use weak passwords
- Hard-code credentials in code
- Give everyone superuser
- Skip system_auth RF setup
- Enable auth without testing
- Store passwords in plain text
- Forget to update apps
Production Security Checklist
- ✅ Authentication: PasswordAuthenticator enabled
- ✅ system_auth RF: Set to 3+ (match cluster RF)
- ✅ Default password: Changed immediately
- ✅ Multiple superusers: Create backup admin accounts
- ✅ User per application: Separate credentials for each service
- ✅ Strong passwords: 12+ characters, mixed case, numbers, symbols
- ✅ Password rotation: Change every 90 days
- ✅ Least privilege: Grant minimal necessary permissions
- ✅ Secrets management: Use vault/secrets manager, not config files
- ✅ Encryption: Enable TLS/SSL (next lesson!)
- ✅ Audit logging: Track who does what
- ✅ Regular audits: Review users and permissions quarterly
Defense in Depth
Authentication is just one layer! Also implement:
- 🔒 Network security: Firewall rules, VPC, security groups
- 🔐 Encryption: TLS for client-to-node and node-to-node
- 🛡️ Authorization: Role-based access control (RBAC)
- 📋 Audit logging: Track all access and changes
- 📊 Monitoring: Alert on failed logins, unusual access patterns
- 🔄 Backups: Encrypted, offsite, tested recovery
- 🚪 JMX security: Secure monitoring interfaces
🎉 You're an Authentication Expert!
Congratulations! You now know how to secure Cassandra with authentication!
🎓 What You Learned:
- 🔍 Authentication basics: Verify WHO you are
- ⚖️ Auth vs Authz: Authentication (who) vs Authorization (what)
- 🛠️ Authenticators: AllowAll, Password, Custom (LDAP/Kerberos)
- ⚡ Enabling auth: Complete step-by-step process
- 👥 User management: Create, modify, delete users
- 💼 Real scenarios: Production enablement, multi-tenant, emergency recovery
- 🔧 Troubleshooting: Fix common authentication issues
- 💡 Best practices: Security checklist, strong passwords, defense in depth
💡 Key Takeaways:
- Always enable auth in production - Default is insecure!
- Set system_auth RF to 3+ - Critical for auth availability
- Change default password - First thing after enabling
- One user per application - Never share credentials
- Strong passwords - 12+ characters, complex
- Multiple superusers - Backup admin accounts
- Test before production - Dev → staging → prod
- Update applications - Configure credentials before enabling
📋 Quick Reference:
🔐 Authentication = First line of defense!
Now add Authorization for complete security →