Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Critical Security Concern: DDS Plugin Lacks Certificate Encryption Support #297

Open
taoyonggang opened this issue Aug 13, 2024 · 0 comments

Comments

@taoyonggang
Copy link

Describe the feature

Dear Zenoh Development Team,

I am writing to express a significant concern regarding the DDS plugin for Zenoh. After attempting to integrate this plugin into our system, we've encountered a critical limitation that renders it unusable in our secure environment.

Key Issue:
The DDS plugin does not support certificate-based encryption, which is a fundamental security requirement in our infrastructure. All our systems utilize certificate encryption for secure communication.

Impact:

  1. Unable to establish secure connections between our DDS systems and Zenoh network.
  2. Creates a potential security vulnerability if implemented without proper encryption.
  3. Renders the plugin unusable in security-conscious environments like ours.

Request:
We strongly urge you to consider adding support for certificate-based encryption to the DDS plugin. This feature is crucial for:

  • Ensuring data confidentiality and integrity
  • Maintaining compliance with security standards
  • Enabling adoption in enterprise and sensitive environments

We believe addressing this limitation would significantly enhance the plugin's usability and security, making it viable for a broader range of applications and users.

We would appreciate your feedback on this matter and would be keen to know if there are plans to address this security gap in future releases.

Thank you for your attention to this critical issue.

Best regards,
Simon

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant