This is an automated email from the ASF dual-hosted git repository. anmolnar pushed a commit to branch branch-3.8 in repository https://gitbox.apache.org/repos/asf/zookeeper.git
commit c0a52c427b56b38938111c8712700b1a70e65df6 Author: Andor Molnar <[email protected]> AuthorDate: Tue Jun 23 15:33:21 2026 -0500 Quorum TLS in FIPS mode accepts hostname-mismatched peer certificates --- .../zookeeper/common/SSLContextAndOptions.java | 21 +++++++++++++++++++++ .../zookeeper/server/quorum/QuorumSSLTest.java | 14 +++++++++----- 2 files changed, 30 insertions(+), 5 deletions(-) diff --git a/zookeeper-server/src/main/java/org/apache/zookeeper/common/SSLContextAndOptions.java b/zookeeper-server/src/main/java/org/apache/zookeeper/common/SSLContextAndOptions.java index 4e61d7b9b..51cca1af3 100644 --- a/zookeeper-server/src/main/java/org/apache/zookeeper/common/SSLContextAndOptions.java +++ b/zookeeper-server/src/main/java/org/apache/zookeeper/common/SSLContextAndOptions.java @@ -184,6 +184,27 @@ private void configureSslParameters(SSLParameters sslParameters, boolean isClien break; } } + + // In FIPS-mode we deal with hostname verification here, + // while in non-FIPS mode verification is handled by ZKTrustManager. + if (X509Util.getFipsMode(config)) { + String clientOrServer = isClientSocket ? "Server" : "Client"; + if (isClientSocket) { + if (x509Util.isServerHostnameVerificationEnabled(config)) { + sslParameters.setEndpointIdentificationAlgorithm("HTTPS"); + if (LOG.isDebugEnabled()) { + LOG.debug("{} hostname verification: enabled HTTPS style endpoint identification algorithm", clientOrServer); + } + } + } else { + if (x509Util.isClientHostnameVerificationEnabled(config)) { + sslParameters.setEndpointIdentificationAlgorithm("HTTPS"); + if (LOG.isDebugEnabled()) { + LOG.debug("{} hostname verification: enabled HTTPS style endpoint identification algorithm", clientOrServer); + } + } + } + } } private String[] getEnabledProtocols(final ZKConfig config, final SSLContext sslContext) { diff --git a/zookeeper-server/src/test/java/org/apache/zookeeper/server/quorum/QuorumSSLTest.java b/zookeeper-server/src/test/java/org/apache/zookeeper/server/quorum/QuorumSSLTest.java index 1096d55b6..48799798e 100644 --- a/zookeeper-server/src/test/java/org/apache/zookeeper/server/quorum/QuorumSSLTest.java +++ b/zookeeper-server/src/test/java/org/apache/zookeeper/server/quorum/QuorumSSLTest.java @@ -621,7 +621,7 @@ private void stopAppendConfigRestartAll(Map<Integer, MainThread> members, String } } - @TestNoFipsOnly + @TestBothFipsModes @Timeout(value = 5, unit = TimeUnit.MINUTES) public void testHostnameVerificationWithInvalidHostname(boolean fipsEnabled) throws Exception { System.setProperty(quorumX509Util.getFipsModeProperty(), Boolean.toString(fipsEnabled)); @@ -639,7 +639,7 @@ public void testHostnameVerificationWithInvalidHostname(boolean fipsEnabled) thr testHostnameVerification(badhostnameKeystorePath, false); } - @TestNoFipsOnly + @TestBothFipsModes @Timeout(value = 5, unit = TimeUnit.MINUTES) public void testHostnameVerificationWithInvalidIPAddress(boolean fipsEnabled) throws Exception { System.setProperty(quorumX509Util.getFipsModeProperty(), Boolean.toString(fipsEnabled)); @@ -657,7 +657,7 @@ public void testHostnameVerificationWithInvalidIPAddress(boolean fipsEnabled) th testHostnameVerification(badhostnameKeystorePath, false); } - @TestNoFipsOnly + @TestBothFipsModes @Timeout(value = 5, unit = TimeUnit.MINUTES) public void testHostnameVerificationWithInvalidIpAddressAndInvalidHostname(boolean fipsEnabled) throws Exception { System.setProperty(quorumX509Util.getFipsModeProperty(), Boolean.toString(fipsEnabled)); @@ -676,7 +676,7 @@ public void testHostnameVerificationWithInvalidIpAddressAndInvalidHostname(boole testHostnameVerification(badhostnameKeystorePath, false); } - @TestNoFipsOnly + @TestBothFipsModes @Timeout(value = 5, unit = TimeUnit.MINUTES) public void testHostnameVerificationForInvalidMultiAddressServerConfig(boolean fipsEnabled) throws Exception { System.setProperty(quorumX509Util.getFipsModeProperty(), Boolean.toString(fipsEnabled)); @@ -698,6 +698,10 @@ public void testHostnameVerificationForInvalidMultiAddressServerConfig(boolean f testHostnameVerification(badhostnameKeystorePath, false); } + /** + * This test is NoFips only, because it needs reverse Dns lookup for client hostname verification, + * which is not supported in Fips mode. + */ @TestNoFipsOnly @Timeout(value = 5, unit = TimeUnit.MINUTES) public void testHostnameVerificationWithInvalidIpAddressAndValidHostname(boolean fipsEnabled) throws Exception { @@ -719,7 +723,7 @@ public void testHostnameVerificationWithInvalidIpAddressAndValidHostname(boolean testHostnameVerification(badhostnameKeystorePath, true); } - @TestNoFipsOnly + @TestBothFipsModes @Timeout(value = 5, unit = TimeUnit.MINUTES) public void testHostnameVerificationWithValidIpAddressAndInvalidHostname(boolean fipsEnabled) throws Exception { System.setProperty(quorumX509Util.getFipsModeProperty(), Boolean.toString(fipsEnabled));
