# Custom Subject Alternative Names now available on Instaclustr for Apache Kafka

[Blog](/blog/)&gt;[Technology](/blog/category/technical/)&gt;Custom Subject Alternative Names now available on Instaclustr for Apache Kafka 

Custom Subject Alternative Names now available on Instaclustr for Apache Kafka
==============================================================================

June 03, 2024 | By [ Varun Ghai](https://www.instaclustr.com/blog/author/varun-ghai/)

 

 

 

 



   [ ](https://x.com/intent/tweet?text=Custom%20Subject%20Alternative%20Names%20now%20available%20on%20Instaclustr%20for%20Apache%20Kafka&url=https://www.instaclustr.com/blog/custom-subject-alternative-names/) [ ](https://www.linkedin.com/shareArticle?mini=true&url=https://www.instaclustr.com/blog/custom-subject-alternative-names/&title=&summary=Custom%20Subject%20Alternative%20Names%20now%20available%20on%20Instaclustr%20for%20Apache%20Kafka&source=) 

**NetApp is pleased to announce support for Subject Alternative Names (SANs) with Instaclustr for Apache Kafka®. You can now use Domain Name Server (DNS) names to securely establish the connection between your Kafka clients and the Kafka cluster.**

### What are Subject Alternative Names?

 Subject Alternative Names (SANs) are an extension to X.509 (a [standard](https://datatracker.ietf.org/doc/html/rfc5280) that defines the format of public key certificates) that allows various forms of identities to be associated with a single certificate.

Traditionally, SSL certificates are associated with a single Common Name (CN), i.e. a certificate would only be valid for the exact hostname listed in the CN field. When a client connected to a server, it checked the server’s certificate to ensure it was valid for the server’s hostname. This meant that if you wanted to secure multiple subdomains or multiple domains, you would need a separate certificate for each one.

When connecting to a Kafka cluster, there are often benefits of addressing via an internal DNS. Connecting via DNS means you can use a name &lt;cluster name&gt;.&lt;your company&gt;.com rather than a list of IPs to specify the connection address.

This provides the advantage that clients only need to be configured with the relevant DNS name for the connection, and if IP addresses change due to node-replacements, the DNS name will still direct to the cluster.

Secure connections need to check the hostname used to connect with the hostname in the certificate and this is where SANs come in. They allow the certificate to contain both the required hostname and the server IP for secure communication with the clusters.

With Instaclustr’s support for SANs, you can now enter the SANs of your choice either at the time of creating a new cluster or by updating them for an existing cluster. You can choose to do so via the Managed Platform Console, our API, or Terraform Provider.

### How to apply changes

To currently apply the changes, the cluster will need to be restarted (which happens automatically). We are working to make it possible to apply such changes without restarts in a future release.

![](https://www.instaclustr.com/wp-content/uploads/Picture-1-4.png)

This feature is now available for all users of Instaclustr for Apache Kafka. Refer to our support page [here](https://www.instaclustr.com/support/documentation/useful-information/subject-alternative-names/) for more details on how to enable and use this new feature on your managed Kafka cluster. Please reach out to us via our [support website](https://support.instaclustr.com/hc/en-us/requests/new) in case of any questions.

 

### About the author

**[Varun Ghai](https://www.instaclustr.com/blog/author/varun-ghai/)** | Product Manager

With a keen focus on product management, Varun brings a wealth of experience and expertise to the team, driving innovation and excellence in the company's Apache Kafka offering.

 

 [ Add Instaclustr as a preferred source on Google ](https://google.com/preferences/source?q=instaclustr.com)



 

 ![mail icon]()#### Get the latest articles for open sourceIn your inbox

 <a class="btn btn-primary btn-popup text-dark" href="">Sign up now</a> 

 

 

 

  ### Related content

 [ Zero Downtime Migration to Instaclustr 

 

 Yes, we can migrate existing Cassandra clusters to Instaclustr without any downtime. Here's what to expect from the process... 

 

 

 

 

 

 

 ](https://www.instaclustr.com/blog/zero-downtime-migration-to-instaclustr/) 

 [ Workflow Comparison: Uber Cadence vs Netflix Conductor 

 

 When choosing what’s right for your company’s opensource workflow needs it is important to know the difference and similarities ... 

 

 

 

 

 

 

 ](https://www.instaclustr.com/blog/workflow-comparison-uber-cadence-vs-netflix-conductor/) 

 [ Will Your Cassandra Database Project Succeed?: The New Stack 

 

 Open source Apache Cassandra® continues to stand out as an enterprise-proven solution for organizations seeking high availability... 

 

 

 

 

 

 

 ](https://www.instaclustr.com/blog/will-your-cassandra-database-project-succeed-the-new-stack/) 

 

  <a class="close-modal" href="">×</a>Sign upto ourNewsletter
-----------------------
