# \#security

**URL:** https://community.temporal.io/tag/security/59.md

[Latest](https://community.temporal.io/latest.md) · [Categories](https://community.temporal.io/categories.md) · [Tags](https://community.temporal.io/tags.md)

---

## [How does internal service auth work with default Authorizer/Claim Mapper?](https://community.temporal.io/t/how-does-internal-service-auth-work-with-default-authorizer-claim-mapper/18610)

<div class="topic-metadata">

**Author:** [@Galo](https://community.temporal.io/u/Galo)\
**Replies:** 2\
**Last updated:** [July 8, 2026, 12:00pm UTC](https://community.temporal.io/t/how-does-internal-service-auth-work-with-default-authorizer-claim-mapper/18610 "2026-07-08T12:00:48Z")

</div>

Hello, I’m trying to enable authentication and authorization using the default authorizer and default claim mapper in a Temporal deployment, but internal services are failing to authorize. Setup Image: temporalio/ser…

---

## [Dependency Security issue CVE-2025-55163](https://community.temporal.io/t/dependency-security-issue-cve-2025-55163/18479)

<div class="topic-metadata">

**Author:** [@edermaxc](https://community.temporal.io/u/edermaxc)\
**Replies:** 7\
**Last updated:** [November 24, 2025, 10:07am UTC](https://community.temporal.io/t/dependency-security-issue-cve-2025-55163/18479 "2025-11-24T10:07:23Z")

</div>

Hi there. Any one know how to fix this vulnerability dependency report about grpc dependency vulnerability CVE-2025-55163?

---

## [Is ringpop's gossiping over TLS?](https://community.temporal.io/t/is-ringpops-gossiping-over-tls/17763)

<div class="topic-metadata">

**Author:** [@gagan](https://community.temporal.io/u/gagan)\
**Replies:** 1\
**Last updated:** [June 26, 2025, 3:58pm UTC](https://community.temporal.io/t/is-ringpops-gossiping-over-tls/17763 "2025-06-26T15:58:44Z")

</div>

Temporal Platform security features | Temporal Platform Documentation document mentions how a temporal cluster can use MTLS for services inside the cluster to talk to one another. I believe this means that temporal ser…

---

## [Patching Vulnerability in Temporal UI Server](https://community.temporal.io/t/patching-vulnerability-in-temporal-ui-server/17705)

<div class="topic-metadata">

**Author:** [@AndrewConfluent](https://community.temporal.io/u/AndrewConfluent)\
**Replies:** 0\
**Last updated:** [June 17, 2025, 6:45pm UTC](https://community.temporal.io/t/patching-vulnerability-in-temporal-ui-server/17705 "2025-06-17T18:45:16Z")

</div>

Temporal UI Server repo master branch has the following vulnerability: jwt-go allows excessive memory allocation during header parsing · CVE-2025-30204 · GitHub Advisory Database · GitHub Can a Codeowner please review c…

---

## [Temporal 1.20+ setting up authentication](https://community.temporal.io/t/temporal-1-20-setting-up-authentication/15537)

<div class="topic-metadata">

**Author:** [@Stimo](https://community.temporal.io/u/Stimo)\
**Replies:** 0\
**Last updated:** [December 5, 2024, 9:25am UTC](https://community.temporal.io/t/temporal-1-20-setting-up-authentication/15537 "2024-12-05T09:25:43Z")

</div>

Hello everyone, I’m currently working on setting up self-hosted Temporal to use Azure AD for authentication but haven’t had success so far. While researching, I came across an article stating that starting from Temporal…

---

## [Custom Claim Mapper](https://community.temporal.io/t/custom-claim-mapper/12706)

<div class="topic-metadata">

**Author:** [@agasser4324](https://community.temporal.io/u/agasser4324)\
**Replies:** 0\
**Last updated:** [July 1, 2024, 12:59pm UTC](https://community.temporal.io/t/custom-claim-mapper/12706 "2024-07-01T12:59:47Z")

</div>

Hello all, I am trying to enable a custom claim mapper for our self-hosted Temporal server. We already have a JWT that is passed to the Temporal frontend, but now I need to map our claims to existing Temporal roles in o…

---

## [Authorization on task queue](https://community.temporal.io/t/authorization-on-task-queue/4780)

<div class="topic-metadata">

**Author:** [@nicolas\_meylan](https://community.temporal.io/u/nicolas_meylan)\
**Replies:** 4\
**Last updated:** [June 13, 2023, 11:20am UTC](https://community.temporal.io/t/authorization-on-task-queue/4780 "2023-06-13T11:20:10Z")

</div>

Hello temporal team, our security team is asking us how we can restrict read/write access to temporal task queues based on microservice. Their concern is that currently any microservice can poll any task queue, it seems…

---

## [Tchannel-go security issue related to older Tally/Thrift](https://community.temporal.io/t/tchannel-go-security-issue-related-to-older-tally-thrift/7378)

<div class="topic-metadata">

**Author:** [@tareque](https://community.temporal.io/u/tareque)\
**Replies:** 7\
**Last updated:** [February 28, 2023, 10:43pm UTC](https://community.temporal.io/t/tchannel-go-security-issue-related-to-older-tally-thrift/7378 "2023-02-28T22:43:42Z")

</div>

Hi folks, GitHub - temporalio/tchannel-go: Go implementation of a multiplexing and framing protocol for RPC calls is importing a fairly old GitHub - uber-go/tally: A Go metrics interface with fast buffered metrics and th…

---

## [Passing sensitive data from workflow to activity](https://community.temporal.io/t/passing-sensitive-data-from-workflow-to-activity/505)

<div class="topic-metadata">

**Author:** [@Gordon\_Bean](https://community.temporal.io/u/Gordon_Bean)\
**Replies:** 1\
**Last updated:** [August 21, 2020, 6:25pm UTC](https://community.temporal.io/t/passing-sensitive-data-from-workflow-to-activity/505 "2020-08-21T18:25:02Z")

</div>

In our application, a workflow begins with a user JWT, which is used to orchestrate activities on behalf of the user across micro-services. Calls to the individual micro-services will be in activities, requiring that th…

---

## [Security vulnerability in temporal image](https://community.temporal.io/t/security-vulnerability-in-temporal-image/6224)

<div class="topic-metadata">

**Author:** [@naresh](https://community.temporal.io/u/naresh)\
**Replies:** 3\
**Last updated:** [October 18, 2022, 7:09pm UTC](https://community.temporal.io/t/security-vulnerability-in-temporal-image/6224 "2022-10-18T19:09:23Z")

</div>

Hi, Our security team detected the “CVE-2022-27664” vulnerability with the temporal image. They are asking us to upgrade the golang version to 1.18.6. I am going through all the temporal images; the latest one (1.18.1) …

---

## [Issue while running tls-full sample](https://community.temporal.io/t/issue-while-running-tls-full-sample/4533)

<div class="topic-metadata">

**Author:** [@Ruchir](https://community.temporal.io/u/Ruchir)\
**Replies:** 4\
**Last updated:** [September 20, 2022, 8:47pm UTC](https://community.temporal.io/t/issue-while-running-tls-full-sample/4533 "2022-09-20T20:47:43Z")

</div>

Hi, Facing an issue while running tls-full sample(samples-server/tls/tls-full at main · temporalio/samples-server · GitHub). Steps followed as below: I have generated the certificates using the given generate-certs.sh…

---

## [How to provide DB credentials to Temporal from a file](https://community.temporal.io/t/how-to-provide-db-credentials-to-temporal-from-a-file/6018)

<div class="topic-metadata">

**Author:** [@joebowbeer](https://community.temporal.io/u/joebowbeer)\
**Replies:** 2\
**Last updated:** [September 20, 2022, 5:47am UTC](https://community.temporal.io/t/how-to-provide-db-credentials-to-temporal-from-a-file/6018 "2022-09-20T05:47:53Z")

</div>

The existingSecret means of providing a database password is implemented to inject the password as an environment variable using valueFrom / secretKeyRef. However, CIS Benchmark generally recommends not passing secrets …

---

## [Interpod communication via istio](https://community.temporal.io/t/interpod-communication-via-istio/5956)

<div class="topic-metadata">

**Author:** [@Karthick](https://community.temporal.io/u/Karthick)\
**Replies:** 3\
**Last updated:** [September 16, 2022, 2:04pm UTC](https://community.temporal.io/t/interpod-communication-via-istio/5956 "2022-09-16T14:04:50Z")

</div>

We are trying to enable istio to control and monitor the communication going on in our temporal deployments. We are able to communicate from Temporal Client to Temporal cluster (via front-end) using istio. But when we i…

---

## [Temporal professional support](https://community.temporal.io/t/temporal-professional-support/4981)

<div class="topic-metadata">

**Author:** [@pradnya.bhalekar](https://community.temporal.io/u/pradnya.bhalekar)\
**Replies:** 2\
**Last updated:** [June 17, 2022, 6:11am UTC](https://community.temporal.io/t/temporal-professional-support/4981 "2022-06-17T06:11:04Z")

</div>

HI, we want to setup Temporal as Production grade setup with Proper Authentication/Authorization setup, is there any professional support available, which we can avail to move things faster, Also, i donot see a way to s…

---

## [Handling client certificate compromise/revocation (MTLS)](https://community.temporal.io/t/handling-client-certificate-compromise-revocation-mtls/3665)

<div class="topic-metadata">

**Author:** [@Liam\_Murray](https://community.temporal.io/u/Liam_Murray)\
**Replies:** 1\
**Last updated:** [June 15, 2022, 3:55pm UTC](https://community.temporal.io/t/handling-client-certificate-compromise-revocation-mtls/3665 "2022-06-15T15:55:12Z")

</div>

I have been looking at the tls-full example for MTLS configuration (and have got it working end to end with Temporal running on EKS). I have a client CA configured the server via “clientCaFiles” but am wondering what is…

---

## [Security/Auth between SDK client and Temporal Server (Helm chart)](https://community.temporal.io/t/security-auth-between-sdk-client-and-temporal-server-helm-chart/4924)

<div class="topic-metadata">

**Author:** [@Patrick\_Klampfl](https://community.temporal.io/u/Patrick_Klampfl)\
**Replies:** 1\
**Last updated:** [June 8, 2022, 5:53pm UTC](https://community.temporal.io/t/security-auth-between-sdk-client-and-temporal-server-helm-chart/4924 "2022-06-08T17:53:11Z")

</div>

For my PoC, I did run both Temporal and the SDK Workers within a Kubernetes cluster, without any kind of security for the cluster-internal communication. With our real world use case, we will also need to make temporal a…

---

## [TLS simple queries](https://community.temporal.io/t/tls-simple-queries/4536)

<div class="topic-metadata">

**Author:** [@Ruchir](https://community.temporal.io/u/Ruchir)\
**Replies:** 1\
**Last updated:** [April 26, 2022, 1:34am UTC](https://community.temporal.io/t/tls-simple-queries/4536 "2022-04-26T01:34:13Z")

</div>

Hi, I had some queries on tls-simple samples-server/tls/tls-simple at main · temporalio/samples-server · GitHub The docker-compose.yaml file contains services of temporal-admin-tools. Following are the env variables m…

---

## [AuthorizationTokenSupplier queries](https://community.temporal.io/t/authorizationtokensupplier-queries/4531)

<div class="topic-metadata">

**Author:** [@Ruchir](https://community.temporal.io/u/Ruchir)\
**Replies:** 1\
**Last updated:** [April 25, 2022, 3:20pm UTC](https://community.temporal.io/t/authorizationtokensupplier-queries/4531 "2022-04-25T15:20:22Z")

</div>

Hi Experts, Can a function be passed as a AuthorizationTokenSupplier , for eg: AuthorizationTokenSupplier tokenSupplier = () -\> return restTemplate.get("http-endpoint-which-returns-jwt-tokens"); Also, in one scenario,…

---

## [How to Use SecurityToken in Namespaces](https://community.temporal.io/t/how-to-use-securitytoken-in-namespaces/2299)

<div class="topic-metadata">

**Author:** [@Tristan\_Fletcher](https://community.temporal.io/u/Tristan_Fletcher)\
**Replies:** 3\
**Last updated:** [June 8, 2021, 7:50pm UTC](https://community.temporal.io/t/how-to-use-securitytoken-in-namespaces/2299 "2021-06-08T19:50:18Z")

</div>

Hey Folks, I was looking into hardening our namespaces and am curious how to properly leverage the SecurityToken feature on Namespaces. As described in the namespace registration help, the token is an “optional token fo…

---

## [Hardening Cassandra User](https://community.temporal.io/t/hardening-cassandra-user/2284)

<div class="topic-metadata">

**Author:** [@Tristan\_Fletcher](https://community.temporal.io/u/Tristan_Fletcher)\
**Replies:** 1\
**Last updated:** [June 1, 2021, 8:44pm UTC](https://community.temporal.io/t/hardening-cassandra-user/2284 "2021-06-01T20:44:52Z")

</div>

We are launching a production instance of Temporal in our cloud and I am looking to harden the user leveraged by Temporal to talk to Cassandra. From the looks of the code, it appears that to run the provisioning tool, t…

---

## [Access Control on Cadence Web](https://community.temporal.io/t/access-control-on-cadence-web/278)

<div class="topic-metadata">

**Author:** [@chandanbhattad](https://community.temporal.io/u/chandanbhattad)\
**Replies:** 3\
**Last updated:** [July 25, 2020, 4:54pm UTC](https://community.temporal.io/t/access-control-on-cadence-web/278 "2020-07-25T16:54:45Z")

</div>

We want to restrict users on the basis of domain. How was access control and authorization done in Uber for cadence web?
