This is an automated email from the ASF dual-hosted git repository.
anmolnar pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/zookeeper.git
The following commit(s) were added to refs/heads/master by this push:
new 4a6893e5a ZOOKEEPER-5054: Netty client should allow every supported
TLS ciphers (addendum)
4a6893e5a is described below
commit 4a6893e5a0e571dd0da96fe859f21fee089b08e3
Author: Balazs Meszaros <[email protected]>
AuthorDate: Mon Oct 5 20:42:03 2026 +0200
ZOOKEEPER-5054: Netty client should allow every supported TLS ciphers
(addendum)
Reviewers: anmolnar
Author: meszibalu
Closes #2470 from meszibalu/zookeeper-5054-master
---
.../org/apache/zookeeper/common/X509UtilTest.java | 30 ++++++++++++++--------
1 file changed, 19 insertions(+), 11 deletions(-)
diff --git
a/zookeeper-server/src/test/java/org/apache/zookeeper/common/X509UtilTest.java
b/zookeeper-server/src/test/java/org/apache/zookeeper/common/X509UtilTest.java
index d11590e97..f3ab55aef 100644
---
a/zookeeper-server/src/test/java/org/apache/zookeeper/common/X509UtilTest.java
+++
b/zookeeper-server/src/test/java/org/apache/zookeeper/common/X509UtilTest.java
@@ -42,6 +42,8 @@
import java.security.cert.X509Certificate;
import java.util.Arrays;
import java.util.List;
+import java.util.Set;
+import java.util.TreeSet;
import java.util.concurrent.Callable;
import java.util.concurrent.CountDownLatch;
import java.util.concurrent.ExecutionException;
@@ -828,27 +830,33 @@ public void
testCreateSSLContext_hostnameVerificationNoCustomTrustStore(X509KeyT
@ParameterizedTest
@MethodSource("data")
- public void testCreateSSLContext_ChaCha20Cipher(X509KeyType caKeyType,
+ public void testCreateSSLContext_AllClientCiphers(X509KeyType caKeyType,
X509KeyType certKeyType, String keyPassword, Integer paramIndex)
throws Exception {
init(caKeyType, certKeyType, keyPassword, paramIndex);
- // TLS_CHACHA20_POLY1305_SHA256 cipher is a mandatory cipher suite on
TLSv1.3,
- // so a client with default configuration must support it.
+ // Netty has an own list of supported ciphers, which is a subset of
+ // JVM's available cipher suites. A client ssl engine must support
every
+ // cipher which is supported by the JVM.
- ZKConfig zkConfig = new ZKConfig();
- zkConfig.setProperty(x509Util.getSslEnabledProtocolsProperty(),
"TLSv1.3");
+ SSLContext defaultContext = SSLContext.getInstance("TLSv1.3");
+ defaultContext.init(null, null, null);
+
+ String[] defaultCipherArray =
defaultContext.getSupportedSSLParameters().getCipherSuites();
+ Set<String> defaultCipherSet = new
TreeSet<>(Arrays.asList(defaultCipherArray));
try (ClientNettyX509Util clientX509Util = new ClientNettyX509Util()) {
- SslContext context =
clientX509Util.createNettySslContextForClient(zkConfig);
+ ZKConfig config = new ZKConfig();
+ config.setProperty(x509Util.getSslEnabledProtocolsProperty(),
"TLSv1.3");
+
+ SslContext clientContext =
clientX509Util.createNettySslContextForClient(config);
UnpooledByteBufAllocator byteBufAllocator = new
UnpooledByteBufAllocator(false);
- SSLEngine engine = context.newEngine(byteBufAllocator);
+ SSLEngine engine = clientContext.newEngine(byteBufAllocator);
- String[] enabledProtocols = engine.getEnabledProtocols();
- assertArrayEquals(new String[] { "TLSv1.3" }, enabledProtocols);
+ String[] clientCipherArray = engine.getEnabledCipherSuites();
+ Set<String> clientCipherSet = new
TreeSet<>(Arrays.asList(clientCipherArray));
- List<String> enabledCipherSuites =
Arrays.asList(engine.getEnabledCipherSuites());
-
assertTrue(enabledCipherSuites.contains("TLS_CHACHA20_POLY1305_SHA256"));
+ assertEquals(defaultCipherSet, clientCipherSet);
}
}