This is an automated email from the ASF dual-hosted git repository.

anmolnar pushed a commit to branch branch-3.8
in repository https://gitbox.apache.org/repos/asf/zookeeper.git

commit c0a52c427b56b38938111c8712700b1a70e65df6
Author: Andor Molnar <[email protected]>
AuthorDate: Tue Jun 23 15:33:21 2026 -0500

    Quorum TLS in FIPS mode accepts hostname-mismatched peer certificates
---
 .../zookeeper/common/SSLContextAndOptions.java      | 21 +++++++++++++++++++++
 .../zookeeper/server/quorum/QuorumSSLTest.java      | 14 +++++++++-----
 2 files changed, 30 insertions(+), 5 deletions(-)

diff --git 
a/zookeeper-server/src/main/java/org/apache/zookeeper/common/SSLContextAndOptions.java
 
b/zookeeper-server/src/main/java/org/apache/zookeeper/common/SSLContextAndOptions.java
index 4e61d7b9b..51cca1af3 100644
--- 
a/zookeeper-server/src/main/java/org/apache/zookeeper/common/SSLContextAndOptions.java
+++ 
b/zookeeper-server/src/main/java/org/apache/zookeeper/common/SSLContextAndOptions.java
@@ -184,6 +184,27 @@ private void configureSslParameters(SSLParameters 
sslParameters, boolean isClien
                 break;
             }
         }
+
+        // In FIPS-mode we deal with hostname verification here,
+        // while in non-FIPS mode verification is handled by ZKTrustManager.
+        if (X509Util.getFipsMode(config)) {
+            String clientOrServer = isClientSocket ? "Server" : "Client";
+            if (isClientSocket) {
+                if (x509Util.isServerHostnameVerificationEnabled(config)) {
+                    sslParameters.setEndpointIdentificationAlgorithm("HTTPS");
+                    if (LOG.isDebugEnabled()) {
+                        LOG.debug("{} hostname verification: enabled HTTPS 
style endpoint identification algorithm", clientOrServer);
+                    }
+                }
+            } else {
+                if (x509Util.isClientHostnameVerificationEnabled(config)) {
+                    sslParameters.setEndpointIdentificationAlgorithm("HTTPS");
+                    if (LOG.isDebugEnabled()) {
+                        LOG.debug("{} hostname verification: enabled HTTPS 
style endpoint identification algorithm", clientOrServer);
+                    }
+                }
+            }
+        }
     }
 
     private String[] getEnabledProtocols(final ZKConfig config, final 
SSLContext sslContext) {
diff --git 
a/zookeeper-server/src/test/java/org/apache/zookeeper/server/quorum/QuorumSSLTest.java
 
b/zookeeper-server/src/test/java/org/apache/zookeeper/server/quorum/QuorumSSLTest.java
index 1096d55b6..48799798e 100644
--- 
a/zookeeper-server/src/test/java/org/apache/zookeeper/server/quorum/QuorumSSLTest.java
+++ 
b/zookeeper-server/src/test/java/org/apache/zookeeper/server/quorum/QuorumSSLTest.java
@@ -621,7 +621,7 @@ private void stopAppendConfigRestartAll(Map<Integer, 
MainThread> members, String
         }
     }
 
-    @TestNoFipsOnly
+    @TestBothFipsModes
     @Timeout(value = 5, unit = TimeUnit.MINUTES)
     public void testHostnameVerificationWithInvalidHostname(boolean 
fipsEnabled) throws Exception {
         System.setProperty(quorumX509Util.getFipsModeProperty(), 
Boolean.toString(fipsEnabled));
@@ -639,7 +639,7 @@ public void 
testHostnameVerificationWithInvalidHostname(boolean fipsEnabled) thr
         testHostnameVerification(badhostnameKeystorePath, false);
     }
 
-    @TestNoFipsOnly
+    @TestBothFipsModes
     @Timeout(value = 5, unit = TimeUnit.MINUTES)
     public void testHostnameVerificationWithInvalidIPAddress(boolean 
fipsEnabled) throws Exception {
         System.setProperty(quorumX509Util.getFipsModeProperty(), 
Boolean.toString(fipsEnabled));
@@ -657,7 +657,7 @@ public void 
testHostnameVerificationWithInvalidIPAddress(boolean fipsEnabled) th
         testHostnameVerification(badhostnameKeystorePath, false);
     }
 
-    @TestNoFipsOnly
+    @TestBothFipsModes
     @Timeout(value = 5, unit = TimeUnit.MINUTES)
     public void 
testHostnameVerificationWithInvalidIpAddressAndInvalidHostname(boolean 
fipsEnabled) throws Exception {
         System.setProperty(quorumX509Util.getFipsModeProperty(), 
Boolean.toString(fipsEnabled));
@@ -676,7 +676,7 @@ public void 
testHostnameVerificationWithInvalidIpAddressAndInvalidHostname(boole
         testHostnameVerification(badhostnameKeystorePath, false);
     }
 
-    @TestNoFipsOnly
+    @TestBothFipsModes
     @Timeout(value = 5, unit = TimeUnit.MINUTES)
     public void 
testHostnameVerificationForInvalidMultiAddressServerConfig(boolean fipsEnabled) 
throws Exception {
         System.setProperty(quorumX509Util.getFipsModeProperty(), 
Boolean.toString(fipsEnabled));
@@ -698,6 +698,10 @@ public void 
testHostnameVerificationForInvalidMultiAddressServerConfig(boolean f
         testHostnameVerification(badhostnameKeystorePath, false);
     }
 
+    /**
+     * This test is NoFips only, because it needs reverse Dns lookup for 
client hostname verification,
+     * which is not supported in Fips mode.
+     */
     @TestNoFipsOnly
     @Timeout(value = 5, unit = TimeUnit.MINUTES)
     public void 
testHostnameVerificationWithInvalidIpAddressAndValidHostname(boolean 
fipsEnabled) throws Exception {
@@ -719,7 +723,7 @@ public void 
testHostnameVerificationWithInvalidIpAddressAndValidHostname(boolean
         testHostnameVerification(badhostnameKeystorePath, true);
     }
 
-    @TestNoFipsOnly
+    @TestBothFipsModes
     @Timeout(value = 5, unit = TimeUnit.MINUTES)
     public void 
testHostnameVerificationWithValidIpAddressAndInvalidHostname(boolean 
fipsEnabled) throws Exception {
         System.setProperty(quorumX509Util.getFipsModeProperty(), 
Boolean.toString(fipsEnabled));

Reply via email to