Encryption in Transit
Protect data in motion with SSL/TLS encryption!
📖 The Story: Rachel's Network Interception
Rachel ran a Cassandra cluster storing medical records. NO encryption enabled. An attacker on the same network ran Wireshark. Captured ALL traffic between nodes and clients. Saw patient names, diagnoses, SSNs - everything in PLAIN TEXT. Sold 100,000 records on dark web. $8M HIPAA fine. Rachel fired. All because data wasn't encrypted in transit.
😱 The Network Sniffing Attack
Monday 9:00 AM - Normal Operations:
Monday 10:00 AM - Attacker Arrives:
- 🔴 Attacker connects laptop to same network
- 🔴 Runs Wireshark (packet sniffer)
- 🔴 Starts capturing ALL traffic
- 🔴 Rachel has NO IDEA this is happening
Monday 10:05 AM - Attacker Sees Everything:
Over Next 3 Days:
- 💀 Attacker captures 100,000 patient records
- 💀 All in plain text: names, SSNs, diagnoses
- 💀 Includes credit card numbers (for payments)
- 💀 Rachel completely unaware
Thursday - The Breach Discovered:
- 📞 Patient calls: "Why is my info on dark web?!"
- 🔍 Investigation finds 100,000 records for sale
- 😱 Security audit discovers NO encryption
- 📰 Press: "Major Healthcare Data Breach"
The Damage:
- 💰 $8M: HIPAA fine (no encryption)
- ⚖️ $15M: Class action lawsuit
- 📉 40%: Stock price drop
- 😡 100,000: Angry patients
- 💼 Rachel: Fired
- 🔒 3 years: CEO prison sentence
✅ With Encryption in Transit
What Would Have Happened:
The Better Outcome:
- ✅ $0: No breach, no fine
- ✅ 0 records: Stolen
- ✅ Rachel: Keeps job, gets promotion
- ✅ Patients: Data stays secure
- ✅ Company: Passes HIPAA audit
SSL/TLS encryption: The difference between $23M loss and $0! 🎯
🔐 What Is Encryption in Transit?
Protect data as it moves!
Definition
Encryption in transit means using SSL/TLS to encrypt data as it travels over the network between:
- Client ↔ Cassandra (client-to-node)
- Node ↔ Node (node-to-node / internode)
Without encryption: All data transmitted in PLAIN TEXT
With encryption: Data encrypted with TLS, unreadable without keys
Why You NEED Encryption
Network Sniffing
Threat: Packet capture tools
- Wireshark, tcpdump
- Can see ALL unencrypted traffic
- Capture queries, results, passwords
- No authentication needed!
- Protection: SSL/TLS ✅
Man-in-the-Middle
Threat: Intercept & modify
- Attacker between client/nodes
- Read data in transit
- Modify requests/responses
- Inject malicious queries
- Protection: SSL/TLS with cert validation ✅
Compliance
Requirement: Regulations
- HIPAA requires encryption
- PCI-DSS requires encryption
- GDPR requires protection
- SOC 2 requires encryption
- Solution: Enable SSL/TLS ✅
📡 Types of Encryption in Transit
Two types to configure!
Client-to-Node
Encrypt: Client ↔ Cassandra
What it protects:
- CQL queries from apps
- Query results
- Authentication credentials
- Client API calls
Port: 9042 (native transport)
Config: client_encryption_options
Essential for public networks!
Node-to-Node (Internode)
Encrypt: Node ↔ Node
What it protects:
- Replication traffic
- Gossip protocol
- Hints delivery
- Repair data streams
Port: 7001 (storage)
Config: server_encryption_options
Critical for multi-DC!
Performance Impact
SSL/TLS adds overhead:
- ⚠️ CPU: 5-15% increase (encryption/decryption)
- ⚠️ Latency: 1-5ms added per request
- ⚠️ Throughput: 10-20% reduction
- ✅ Worth it: Security > Performance
- ✅ Mitigation: Use hardware AES acceleration
🔗 Configuring Node-to-Node Encryption
Secure internode communication!
Generate SSL Certificates
Create keystore and truststore
Create Truststore (Import All Certs)
Each node needs to trust all other nodes
Configure cassandra.yaml
Enable node-to-node encryption
Rolling Restart Cluster
Enable encryption without downtime
Internode Encryption Options
| Option | Description | Use Case |
|---|---|---|
| none | No encryption | Development only (NEVER production!) |
| dc | Encrypt between datacenters only | Multi-DC over WAN, trusted LAN |
| rack | Encrypt between racks only | Trusted DC, untrusted racks |
| all | Encrypt all internode traffic | Maximum security (RECOMMENDED) |
💻 Configuring Client-to-Node Encryption
Secure client connections!
Use Same Certificates (or Generate New)
Can reuse node certificates or create separate ones
Configure cassandra.yaml
Enable client encryption
Update Client Applications
Configure clients to use SSL
📜 Certificate Management
Best practices for certs!
Certificate Authority (CA) vs Self-Signed
Self-Signed (Shown Above):
- ✅ Easy to set up
- ✅ Free
- ✅ Good for internal clusters
- ⚠️ Manual trust management
- ⚠️ Not suitable for public-facing
CA-Signed (Production Recommended):
- ✅ Trusted by default
- ✅ Automatic validation
- ✅ Better for compliance
- ✅ Certificate revocation
- ⚠️ Costs money (Let's Encrypt is free!)
Certificate Expiration
Certificate Rotation
Certificate Storage Security
- File Permissions: chmod 600 .keystore .truststore
- Ownership: chown cassandra:cassandra
- Passwords: Use strong passwords, don't hardcode
- Backup: Store certs securely, encrypted backups
- Access: Limit who can access keystores
✅ Testing & Verification
Confirm encryption is working!
1. Check Cassandra Logs
2. Test Client Connection
3. Verify with openssl
4. Packet Capture Test
💡 Encryption Best Practices
Do it right!
DO
- Enable BOTH client-to-node AND node-to-node
- Use TLS 1.2 or higher
- Use strong cipher suites
- Use CA-signed certificates in production
- Rotate certificates annually
- Monitor certificate expiration
- Test in staging first
- Secure keystore files (chmod 600)
DON'T
- Run production without encryption
- Use weak passwords (cassandra/cassandra)
- Hardcode passwords in config
- Let certificates expire
- Use SSLv3 or TLS 1.0 (insecure!)
- Forget to update clients
- Skip testing after enabling
- Store keystores in public locations
Complete Encryption Checklist
| Task | Details | Done? |
|---|---|---|
| Generate Certificates | Keystore + truststore for each node | ☐ |
| Node-to-Node SSL | server_encryption_options enabled | ☐ |
| Client-to-Node SSL | client_encryption_options enabled | ☐ |
| Update Clients | All apps configured for SSL | ☐ |
| Test Connections | cqlsh --ssl works | ☐ |
| Verify Encryption | Packet capture shows encrypted data | ☐ |
| Secure Keystores | chmod 600, proper ownership | ☐ |
| Monitor Expiration | Alerts set for 30 days before expiry | ☐ |
| Document Process | Certificate locations, passwords stored securely | ☐ |
| Compliance | Meets HIPAA/PCI/GDPR requirements | ☐ |
Common Issues & Solutions
| Issue | Cause | Solution |
|---|---|---|
| Node won't start | Wrong keystore path/password | Check cassandra.yaml config, verify files exist |
| Client can't connect | Missing SSL config in client | Add SSL context to client connection |
| Certificate expired | Forgot to renew | Generate new certs, rolling restart |
| Handshake failed | Cert not in truststore | Import certificate to truststore |
| Performance degradation | SSL overhead | Enable hardware AES, upgrade CPUs |
🎉 Master Encryption in Transit!
You now know how to secure Cassandra communication with SSL/TLS!
🎓 What You Learned:
- 📖 Rachel's breach: $23M loss from unencrypted traffic
- 🔐 What it is: SSL/TLS encryption for data in motion
- 📡 Two types: Client-to-node + node-to-node
- 🔗 Node-to-node: Complete setup with certificates
- 💻 Client-to-node: Secure client connections
- 📜 Certificates: Generation, rotation, expiration
- ✅ Testing: Verify encryption is working
- 💡 Best practices: TLS 1.2+, strong ciphers, monitoring
💡 Key Takeaways:
- Enable BOTH types - Client-to-node AND node-to-node
- Use proper certificates - CA-signed for production
- TLS 1.2 minimum - Older versions are insecure
- Monitor expiration - Expired certs = cluster down
- Test thoroughly - Packet capture to verify
- Compliance requirement - HIPAA/PCI/GDPR mandate it
📋 Quick Setup (4 Steps):
🔒 Before vs After:
❌ Without Encryption
- Traffic in plain text
- Anyone can sniff packets
- Passwords visible
- Fails compliance
- $23M breach risk
✅ With Encryption
- All traffic encrypted
- Packet capture useless
- Credentials protected
- Meets compliance
- $0 breach risk
🔐 Remember Rachel: SSL/TLS = $23M saved! 🎯
Enable encryption NOW!
📱 Responsive Ad 📱