This is an automated email from the ASF dual-hosted git repository.
anmolnar pushed a commit to branch branch-3.9
in repository https://gitbox.apache.org/repos/asf/zookeeper.git
The following commit(s) were added to refs/heads/branch-3.9 by this push:
new 5b3f51fc5 ZOOKEEPER-5054: Netty client should allow every supported
TLS ciphers
5b3f51fc5 is described below
commit 5b3f51fc5e7830d61e8b23f69a2d5a5a8978bce9
Author: Balazs Meszaros <[email protected]>
AuthorDate: Thu Oct 1 17:33:30 2026 +0200
ZOOKEEPER-5054: Netty client should allow every supported TLS ciphers
Author: meszibalu
Closes #2465 from meszibalu/zookeeper-5054
---
.../apache/zookeeper/common/ClientX509Util.java | 4 ++-
.../org/apache/zookeeper/common/X509UtilTest.java | 29 ++++++++++++++++++++--
2 files changed, 30 insertions(+), 3 deletions(-)
diff --git
a/zookeeper-server/src/main/java/org/apache/zookeeper/common/ClientX509Util.java
b/zookeeper-server/src/main/java/org/apache/zookeeper/common/ClientX509Util.java
index 760a5a01f..017a7a240 100644
---
a/zookeeper-server/src/main/java/org/apache/zookeeper/common/ClientX509Util.java
+++
b/zookeeper-server/src/main/java/org/apache/zookeeper/common/ClientX509Util.java
@@ -100,7 +100,9 @@ public SslContext createNettySslContextForClient(ZKConfig
config)
sslContextBuilder.protocols(enabledProtocols);
}
Iterable<String> enabledCiphers = getCipherSuites(config);
- if (enabledCiphers != null) {
+ if (enabledCiphers == null) {
+ sslContextBuilder.ciphers(null,
IdentityCipherSuiteFilter.INSTANCE_DEFAULTING_TO_SUPPORTED_CIPHERS);
+ } else {
sslContextBuilder.ciphers(enabledCiphers);
}
sslContextBuilder.sslProvider(getSslProvider(config));
diff --git
a/zookeeper-server/src/test/java/org/apache/zookeeper/common/X509UtilTest.java
b/zookeeper-server/src/test/java/org/apache/zookeeper/common/X509UtilTest.java
index f76b91ddf..8dc988fed 100644
---
a/zookeeper-server/src/test/java/org/apache/zookeeper/common/X509UtilTest.java
+++
b/zookeeper-server/src/test/java/org/apache/zookeeper/common/X509UtilTest.java
@@ -63,7 +63,6 @@
import org.junit.jupiter.params.ParameterizedTest;
import org.junit.jupiter.params.provider.MethodSource;
-
public class X509UtilTest extends BaseX509ParameterizedTestCase {
private X509Util x509Util;
@@ -793,7 +792,7 @@ public void testCreateSSLContext_ocspWithJreProvider(
throws Exception {
init(caKeyType, certKeyType, keyPassword, paramIndex);
ZKConfig zkConfig = new ZKConfig();
- try (ClientX509Util clientX509Util = new ClientX509Util();) {
+ try (ClientX509Util clientX509Util = new ClientX509Util()) {
zkConfig.setProperty(clientX509Util.getSslOcspEnabledProperty(),
"true");
// Must not throw IllegalArgumentException
clientX509Util.createSSLContext(zkConfig);
@@ -822,6 +821,32 @@ public void
testCreateSSLContext_hostnameVerificationNoCustomTrustStore(X509KeyT
}
}
+ @ParameterizedTest
+ @MethodSource("data")
+ public void testCreateSSLContext_ChaCha20Cipher(X509KeyType caKeyType,
+ X509KeyType certKeyType, String keyPassword, Integer paramIndex)
throws Exception {
+ init(caKeyType, certKeyType, keyPassword, paramIndex);
+
+ // TLS_CHACHA20_POLY1305_SHA256 cipher is a mandatory cipher suite on
TLSv1.3,
+ // so a client with default configuration must support it.
+
+ ZKConfig zkConfig = new ZKConfig();
+ zkConfig.setProperty(x509Util.getSslEnabledProtocolsProperty(),
"TLSv1.3");
+
+ try (ClientX509Util clientX509Util = new ClientX509Util()) {
+ SslContext context =
clientX509Util.createNettySslContextForClient(zkConfig);
+
+ UnpooledByteBufAllocator byteBufAllocator = new
UnpooledByteBufAllocator(false);
+ SSLEngine engine = context.newEngine(byteBufAllocator);
+
+ String[] enabledProtocols = engine.getEnabledProtocols();
+ assertArrayEquals(new String[] { "TLSv1.3" }, enabledProtocols);
+
+ List<String> enabledCipherSuites =
Arrays.asList(engine.getEnabledCipherSuites());
+
assertTrue(enabledCipherSuites.contains("TLS_CHACHA20_POLY1305_SHA256"));
+ }
+ }
+
private static void forceClose(Socket s) {
if (s == null || s.isClosed()) {
return;