This is an automated email from the ASF dual-hosted git repository.

anmolnar pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/zookeeper.git


The following commit(s) were added to refs/heads/master by this push:
     new aafd344ee ZOOKEEPER-5054: Netty client should allow every supported 
TLS ciphers
aafd344ee is described below

commit aafd344eeeb5090e0e24126ea9e28133a77c22b0
Author: Balazs Meszaros <[email protected]>
AuthorDate: Thu Oct 1 02:39:37 2026 +0200

    ZOOKEEPER-5054: Netty client should allow every supported TLS ciphers
    
    Reviewers: anmolnar, PDavid
    Author: meszibalu
    Closes #2404 from meszibalu/zookeeper-5054
---
 .../zookeeper/common/ClientNettyX509Util.java      |  4 ++-
 .../org/apache/zookeeper/common/X509UtilTest.java  | 29 ++++++++++++++++++++--
 2 files changed, 30 insertions(+), 3 deletions(-)

diff --git 
a/zookeeper-server/src/main/java/org/apache/zookeeper/common/ClientNettyX509Util.java
 
b/zookeeper-server/src/main/java/org/apache/zookeeper/common/ClientNettyX509Util.java
index 227fdde8c..09e9ee8a6 100644
--- 
a/zookeeper-server/src/main/java/org/apache/zookeeper/common/ClientNettyX509Util.java
+++ 
b/zookeeper-server/src/main/java/org/apache/zookeeper/common/ClientNettyX509Util.java
@@ -72,7 +72,9 @@ public SslContext createNettySslContextForClient(ZKConfig 
config)
             sslContextBuilder.protocols(enabledProtocols);
         }
         Iterable<String> enabledCiphers = getCipherSuites(config);
-        if (enabledCiphers != null) {
+        if (enabledCiphers == null) {
+            sslContextBuilder.ciphers(null, 
IdentityCipherSuiteFilter.INSTANCE_DEFAULTING_TO_SUPPORTED_CIPHERS);
+        } else {
             sslContextBuilder.ciphers(enabledCiphers);
         }
         sslContextBuilder.sslProvider(getSslProvider(config));
diff --git 
a/zookeeper-server/src/test/java/org/apache/zookeeper/common/X509UtilTest.java 
b/zookeeper-server/src/test/java/org/apache/zookeeper/common/X509UtilTest.java
index 494bf6c1e..d11590e97 100644
--- 
a/zookeeper-server/src/test/java/org/apache/zookeeper/common/X509UtilTest.java
+++ 
b/zookeeper-server/src/test/java/org/apache/zookeeper/common/X509UtilTest.java
@@ -68,7 +68,6 @@
 import org.junit.jupiter.params.ParameterizedTest;
 import org.junit.jupiter.params.provider.MethodSource;
 
-
 public class X509UtilTest extends BaseX509ParameterizedTestCase {
 
     private X509Util x509Util;
@@ -798,7 +797,7 @@ public void testCreateSSLContext_ocspWithJreProvider(
             throws Exception {
         init(caKeyType, certKeyType, keyPassword, paramIndex);
         ZKConfig zkConfig = new ZKConfig();
-        try (ClientX509Util clientX509Util = new ClientX509Util();) {
+        try (ClientX509Util clientX509Util = new ClientX509Util()) {
             zkConfig.setProperty(clientX509Util.getSslOcspEnabledProperty(), 
"true");
             // Must not throw IllegalArgumentException
             clientX509Util.createSSLContext(zkConfig);
@@ -827,6 +826,32 @@ public void 
testCreateSSLContext_hostnameVerificationNoCustomTrustStore(X509KeyT
         }
     }
 
+    @ParameterizedTest
+    @MethodSource("data")
+    public void testCreateSSLContext_ChaCha20Cipher(X509KeyType caKeyType,
+            X509KeyType certKeyType, String keyPassword, Integer paramIndex) 
throws Exception {
+        init(caKeyType, certKeyType, keyPassword, paramIndex);
+
+        // TLS_CHACHA20_POLY1305_SHA256 cipher is a mandatory cipher suite on 
TLSv1.3,
+        // so a client with default configuration must support it.
+
+        ZKConfig zkConfig = new ZKConfig();
+        zkConfig.setProperty(x509Util.getSslEnabledProtocolsProperty(), 
"TLSv1.3");
+
+        try (ClientNettyX509Util clientX509Util = new ClientNettyX509Util()) {
+            SslContext context = 
clientX509Util.createNettySslContextForClient(zkConfig);
+
+            UnpooledByteBufAllocator byteBufAllocator = new 
UnpooledByteBufAllocator(false);
+            SSLEngine engine = context.newEngine(byteBufAllocator);
+
+            String[] enabledProtocols = engine.getEnabledProtocols();
+            assertArrayEquals(new String[] { "TLSv1.3" }, enabledProtocols);
+
+            List<String> enabledCipherSuites = 
Arrays.asList(engine.getEnabledCipherSuites());
+            
assertTrue(enabledCipherSuites.contains("TLS_CHACHA20_POLY1305_SHA256"));
+        }
+    }
+
     private static void forceClose(Socket s) {
         if (s == null || s.isClosed()) {
             return;

Reply via email to