This is an automated email from the ASF dual-hosted git repository.

anmolnar pushed a commit to branch branch-3.9
in repository https://gitbox.apache.org/repos/asf/zookeeper.git


The following commit(s) were added to refs/heads/branch-3.9 by this push:
     new 96ff69049 ZOOKEEPER-5054: Netty client should allow every supported 
TLS ciphers…
96ff69049 is described below

commit 96ff690499faf367b3a704d9a00fa58bc376c1cc
Author: Balazs Meszaros <[email protected]>
AuthorDate: Mon Oct 5 20:42:54 2026 +0200

    ZOOKEEPER-5054: Netty client should allow every supported TLS ciphers…
    
    Reviewers: anmolnar
    Author: meszibalu
    Closes #2469 from meszibalu/zookeeper-5054
---
 .../org/apache/zookeeper/common/X509UtilTest.java  | 30 ++++++++++++++--------
 1 file changed, 19 insertions(+), 11 deletions(-)

diff --git 
a/zookeeper-server/src/test/java/org/apache/zookeeper/common/X509UtilTest.java 
b/zookeeper-server/src/test/java/org/apache/zookeeper/common/X509UtilTest.java
index 8dc988fed..1b4109c2e 100644
--- 
a/zookeeper-server/src/test/java/org/apache/zookeeper/common/X509UtilTest.java
+++ 
b/zookeeper-server/src/test/java/org/apache/zookeeper/common/X509UtilTest.java
@@ -37,6 +37,8 @@
 import java.security.NoSuchAlgorithmException;
 import java.util.Arrays;
 import java.util.List;
+import java.util.Set;
+import java.util.TreeSet;
 import java.util.concurrent.Callable;
 import java.util.concurrent.CountDownLatch;
 import java.util.concurrent.ExecutionException;
@@ -823,27 +825,33 @@ public void 
testCreateSSLContext_hostnameVerificationNoCustomTrustStore(X509KeyT
 
     @ParameterizedTest
     @MethodSource("data")
-    public void testCreateSSLContext_ChaCha20Cipher(X509KeyType caKeyType,
+    public void testCreateSSLContext_AllClientCiphers(X509KeyType caKeyType,
             X509KeyType certKeyType, String keyPassword, Integer paramIndex) 
throws Exception {
         init(caKeyType, certKeyType, keyPassword, paramIndex);
 
-        // TLS_CHACHA20_POLY1305_SHA256 cipher is a mandatory cipher suite on 
TLSv1.3,
-        // so a client with default configuration must support it.
+        // Netty has an own list of supported ciphers, which is a subset of
+        // JVM's available cipher suites. A client ssl engine must support 
every
+        // cipher which is supported by the JVM.
 
-        ZKConfig zkConfig = new ZKConfig();
-        zkConfig.setProperty(x509Util.getSslEnabledProtocolsProperty(), 
"TLSv1.3");
+        SSLContext defaultContext = SSLContext.getInstance("TLSv1.3");
+        defaultContext.init(null, null, null);
+
+        String[] defaultCipherArray = 
defaultContext.getSupportedSSLParameters().getCipherSuites();
+        Set<String> defaultCipherSet = new 
TreeSet<>(Arrays.asList(defaultCipherArray));
 
         try (ClientX509Util clientX509Util = new ClientX509Util()) {
-            SslContext context = 
clientX509Util.createNettySslContextForClient(zkConfig);
+            ZKConfig config = new ZKConfig();
+            config.setProperty(x509Util.getSslEnabledProtocolsProperty(), 
"TLSv1.3");
+
+            SslContext clientContext = 
clientX509Util.createNettySslContextForClient(config);
 
             UnpooledByteBufAllocator byteBufAllocator = new 
UnpooledByteBufAllocator(false);
-            SSLEngine engine = context.newEngine(byteBufAllocator);
+            SSLEngine engine = clientContext.newEngine(byteBufAllocator);
 
-            String[] enabledProtocols = engine.getEnabledProtocols();
-            assertArrayEquals(new String[] { "TLSv1.3" }, enabledProtocols);
+            String[] clientCipherArray = engine.getEnabledCipherSuites();
+            Set<String> clientCipherSet = new 
TreeSet<>(Arrays.asList(clientCipherArray));
 
-            List<String> enabledCipherSuites = 
Arrays.asList(engine.getEnabledCipherSuites());
-            
assertTrue(enabledCipherSuites.contains("TLS_CHACHA20_POLY1305_SHA256"));
+            assertEquals(defaultCipherSet, clientCipherSet);
         }
     }
 

Reply via email to