enhancement(sources): add subject_altnames to TLS client metadata - #26113
Open
emillen wants to merge 1 commit into
Open
enhancement(sources): add subject_altnames to TLS client metadata#26113emillen wants to merge 1 commit into
emillen wants to merge 1 commit into
Conversation
Contributor
|
All contributors have signed the CLA ✍️ ✅ |
Author
|
I have read the CLA Document and I hereby sign the CLA |
pront
approved these changes
Aug 14, 2026
pront
enabled auto-merge
August 14, 2026 20:54
github-merge-queue
Bot
removed this pull request from the merge queue due to failed status checks
Aug 14, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
tls_client_metadata(emitted by TLS sources whenclient_metadata_keyis set)currently exposes only the client certificate
subject. This PR addssubject_altnameswith the certificate's Subject Alternative Names — the realentity identity in modern/mTLS PKI — so operators can distinguish, enrich,
route, and audit clients by their SANs.
openssl x509 -text(e.g.
DNS:localhost,IP Address:127.0.0.1).client_metadata_key(fluent, logstash, socket,statsd, syslog, TCP-mode dnstap) via the shared
build_tls_client_metadata.logs_output.htmlso the nestedsubject/subject_altnamesoptions render on the reference docs.
References
Closes: #26111
Related: #11905 (original
tls_client_metadatafeature)Vector configuration
Receiver (
syslogwith mTLS):Sender:
demo_logs→socketsink over TLS with a client cert that has SANs.How did you test this PR?
receiver output included
"tls_subject_altnames":"DNS:localhost,IP Address:127.0.0.1".CertificateMetadata::subject_altnames(vector-core) andbuild_tls_client_metadata(key present with SANs, absent without).make fmt,make check-fmt,make check-markdown,make check-generated-docspass; scoped clippy on
vector/vector-coreclean.(Full
make check-clippyis blocked by a pre-existingkrb5-srcC-dependencybuild failure under newer GCC via kafka's
gssapi-vendoredfeature.)Is this a breaking change?
Does this PR include user facing changes?
no-changeloglabel to this PR.