This is an automated email from the ASF dual-hosted git repository.

anmolnar pushed a commit to branch branch-3.9
in repository https://gitbox.apache.org/repos/asf/zookeeper.git


The following commit(s) were added to refs/heads/branch-3.9 by this push:
     new 5b3f51fc5 ZOOKEEPER-5054: Netty client should allow every supported 
TLS ciphers
5b3f51fc5 is described below

commit 5b3f51fc5e7830d61e8b23f69a2d5a5a8978bce9
Author: Balazs Meszaros <[email protected]>
AuthorDate: Thu Oct 1 17:33:30 2026 +0200

    ZOOKEEPER-5054: Netty client should allow every supported TLS ciphers
    
    Author: meszibalu
    Closes #2465 from meszibalu/zookeeper-5054
---
 .../apache/zookeeper/common/ClientX509Util.java    |  4 ++-
 .../org/apache/zookeeper/common/X509UtilTest.java  | 29 ++++++++++++++++++++--
 2 files changed, 30 insertions(+), 3 deletions(-)

diff --git 
a/zookeeper-server/src/main/java/org/apache/zookeeper/common/ClientX509Util.java
 
b/zookeeper-server/src/main/java/org/apache/zookeeper/common/ClientX509Util.java
index 760a5a01f..017a7a240 100644
--- 
a/zookeeper-server/src/main/java/org/apache/zookeeper/common/ClientX509Util.java
+++ 
b/zookeeper-server/src/main/java/org/apache/zookeeper/common/ClientX509Util.java
@@ -100,7 +100,9 @@ public SslContext createNettySslContextForClient(ZKConfig 
config)
             sslContextBuilder.protocols(enabledProtocols);
         }
         Iterable<String> enabledCiphers = getCipherSuites(config);
-        if (enabledCiphers != null) {
+        if (enabledCiphers == null) {
+            sslContextBuilder.ciphers(null, 
IdentityCipherSuiteFilter.INSTANCE_DEFAULTING_TO_SUPPORTED_CIPHERS);
+        } else {
             sslContextBuilder.ciphers(enabledCiphers);
         }
         sslContextBuilder.sslProvider(getSslProvider(config));
diff --git 
a/zookeeper-server/src/test/java/org/apache/zookeeper/common/X509UtilTest.java 
b/zookeeper-server/src/test/java/org/apache/zookeeper/common/X509UtilTest.java
index f76b91ddf..8dc988fed 100644
--- 
a/zookeeper-server/src/test/java/org/apache/zookeeper/common/X509UtilTest.java
+++ 
b/zookeeper-server/src/test/java/org/apache/zookeeper/common/X509UtilTest.java
@@ -63,7 +63,6 @@
 import org.junit.jupiter.params.ParameterizedTest;
 import org.junit.jupiter.params.provider.MethodSource;
 
-
 public class X509UtilTest extends BaseX509ParameterizedTestCase {
 
     private X509Util x509Util;
@@ -793,7 +792,7 @@ public void testCreateSSLContext_ocspWithJreProvider(
             throws Exception {
         init(caKeyType, certKeyType, keyPassword, paramIndex);
         ZKConfig zkConfig = new ZKConfig();
-        try (ClientX509Util clientX509Util = new ClientX509Util();) {
+        try (ClientX509Util clientX509Util = new ClientX509Util()) {
             zkConfig.setProperty(clientX509Util.getSslOcspEnabledProperty(), 
"true");
             // Must not throw IllegalArgumentException
             clientX509Util.createSSLContext(zkConfig);
@@ -822,6 +821,32 @@ public void 
testCreateSSLContext_hostnameVerificationNoCustomTrustStore(X509KeyT
         }
     }
 
+    @ParameterizedTest
+    @MethodSource("data")
+    public void testCreateSSLContext_ChaCha20Cipher(X509KeyType caKeyType,
+            X509KeyType certKeyType, String keyPassword, Integer paramIndex) 
throws Exception {
+        init(caKeyType, certKeyType, keyPassword, paramIndex);
+
+        // TLS_CHACHA20_POLY1305_SHA256 cipher is a mandatory cipher suite on 
TLSv1.3,
+        // so a client with default configuration must support it.
+
+        ZKConfig zkConfig = new ZKConfig();
+        zkConfig.setProperty(x509Util.getSslEnabledProtocolsProperty(), 
"TLSv1.3");
+
+        try (ClientX509Util clientX509Util = new ClientX509Util()) {
+            SslContext context = 
clientX509Util.createNettySslContextForClient(zkConfig);
+
+            UnpooledByteBufAllocator byteBufAllocator = new 
UnpooledByteBufAllocator(false);
+            SSLEngine engine = context.newEngine(byteBufAllocator);
+
+            String[] enabledProtocols = engine.getEnabledProtocols();
+            assertArrayEquals(new String[] { "TLSv1.3" }, enabledProtocols);
+
+            List<String> enabledCipherSuites = 
Arrays.asList(engine.getEnabledCipherSuites());
+            
assertTrue(enabledCipherSuites.contains("TLS_CHACHA20_POLY1305_SHA256"));
+        }
+    }
+
     private static void forceClose(Socket s) {
         if (s == null || s.isClosed()) {
             return;

Reply via email to