This is an automated email from the ASF dual-hosted git repository.
anmolnar pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/zookeeper.git
The following commit(s) were added to refs/heads/master by this push:
new aafd344ee ZOOKEEPER-5054: Netty client should allow every supported
TLS ciphers
aafd344ee is described below
commit aafd344eeeb5090e0e24126ea9e28133a77c22b0
Author: Balazs Meszaros <[email protected]>
AuthorDate: Thu Oct 1 02:39:37 2026 +0200
ZOOKEEPER-5054: Netty client should allow every supported TLS ciphers
Reviewers: anmolnar, PDavid
Author: meszibalu
Closes #2404 from meszibalu/zookeeper-5054
---
.../zookeeper/common/ClientNettyX509Util.java | 4 ++-
.../org/apache/zookeeper/common/X509UtilTest.java | 29 ++++++++++++++++++++--
2 files changed, 30 insertions(+), 3 deletions(-)
diff --git
a/zookeeper-server/src/main/java/org/apache/zookeeper/common/ClientNettyX509Util.java
b/zookeeper-server/src/main/java/org/apache/zookeeper/common/ClientNettyX509Util.java
index 227fdde8c..09e9ee8a6 100644
---
a/zookeeper-server/src/main/java/org/apache/zookeeper/common/ClientNettyX509Util.java
+++
b/zookeeper-server/src/main/java/org/apache/zookeeper/common/ClientNettyX509Util.java
@@ -72,7 +72,9 @@ public SslContext createNettySslContextForClient(ZKConfig
config)
sslContextBuilder.protocols(enabledProtocols);
}
Iterable<String> enabledCiphers = getCipherSuites(config);
- if (enabledCiphers != null) {
+ if (enabledCiphers == null) {
+ sslContextBuilder.ciphers(null,
IdentityCipherSuiteFilter.INSTANCE_DEFAULTING_TO_SUPPORTED_CIPHERS);
+ } else {
sslContextBuilder.ciphers(enabledCiphers);
}
sslContextBuilder.sslProvider(getSslProvider(config));
diff --git
a/zookeeper-server/src/test/java/org/apache/zookeeper/common/X509UtilTest.java
b/zookeeper-server/src/test/java/org/apache/zookeeper/common/X509UtilTest.java
index 494bf6c1e..d11590e97 100644
---
a/zookeeper-server/src/test/java/org/apache/zookeeper/common/X509UtilTest.java
+++
b/zookeeper-server/src/test/java/org/apache/zookeeper/common/X509UtilTest.java
@@ -68,7 +68,6 @@
import org.junit.jupiter.params.ParameterizedTest;
import org.junit.jupiter.params.provider.MethodSource;
-
public class X509UtilTest extends BaseX509ParameterizedTestCase {
private X509Util x509Util;
@@ -798,7 +797,7 @@ public void testCreateSSLContext_ocspWithJreProvider(
throws Exception {
init(caKeyType, certKeyType, keyPassword, paramIndex);
ZKConfig zkConfig = new ZKConfig();
- try (ClientX509Util clientX509Util = new ClientX509Util();) {
+ try (ClientX509Util clientX509Util = new ClientX509Util()) {
zkConfig.setProperty(clientX509Util.getSslOcspEnabledProperty(),
"true");
// Must not throw IllegalArgumentException
clientX509Util.createSSLContext(zkConfig);
@@ -827,6 +826,32 @@ public void
testCreateSSLContext_hostnameVerificationNoCustomTrustStore(X509KeyT
}
}
+ @ParameterizedTest
+ @MethodSource("data")
+ public void testCreateSSLContext_ChaCha20Cipher(X509KeyType caKeyType,
+ X509KeyType certKeyType, String keyPassword, Integer paramIndex)
throws Exception {
+ init(caKeyType, certKeyType, keyPassword, paramIndex);
+
+ // TLS_CHACHA20_POLY1305_SHA256 cipher is a mandatory cipher suite on
TLSv1.3,
+ // so a client with default configuration must support it.
+
+ ZKConfig zkConfig = new ZKConfig();
+ zkConfig.setProperty(x509Util.getSslEnabledProtocolsProperty(),
"TLSv1.3");
+
+ try (ClientNettyX509Util clientX509Util = new ClientNettyX509Util()) {
+ SslContext context =
clientX509Util.createNettySslContextForClient(zkConfig);
+
+ UnpooledByteBufAllocator byteBufAllocator = new
UnpooledByteBufAllocator(false);
+ SSLEngine engine = context.newEngine(byteBufAllocator);
+
+ String[] enabledProtocols = engine.getEnabledProtocols();
+ assertArrayEquals(new String[] { "TLSv1.3" }, enabledProtocols);
+
+ List<String> enabledCipherSuites =
Arrays.asList(engine.getEnabledCipherSuites());
+
assertTrue(enabledCipherSuites.contains("TLS_CHACHA20_POLY1305_SHA256"));
+ }
+ }
+
private static void forceClose(Socket s) {
if (s == null || s.isClosed()) {
return;