[
https://issues.apache.org/jira/browse/CXF-8326?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17182406#comment-17182406
]
Alain Sellerin edited comment on CXF-8326 at 8/22/20, 3:01 PM:
---------------------------------------------------------------
Hi,
I'm able to reproduce the problem in testAESIncludedTLSv11UsingSSLContext()
If instruction
{noformat}
final Greeter port = service.getHttpsPort();{noformat}
Is replaced with
{noformat}
final Greeter port = service.getPort(Greeter.class);{noformat}
The test is failing and negotiated ssl version is TLSv1.2 instead of TLSv1.1
Tested with
{noformat}
mvn test -Dtest=CipherSuitesTest#testAESIncludedTLSv11UsingSSLContext
-Djavax.net.debug=ssl{noformat}
was (Author: asellerin):
Hi,
I'm able to reproduce the problem in testAESIncludedTLSv11UsingSSLContext()
If instruction
{noformat}
final Greeter port = service.getHttpsPort();{noformat}
Is replaced with
{noformat}
final Greeter port = service.getPort(Greeter.class);{noformat}
The test is failing and negotiated ssl version is TLSv1.2 instead of TLSv1.0
Tested with
{noformat}
mvn test -Dtest=CipherSuitesTest#testAESIncludedTLSv11UsingSSLContext
-Djavax.net.debug=ssl{noformat}
> SSLContext protocol version is ignored
> --------------------------------------
>
> Key: CXF-8326
> URL: https://issues.apache.org/jira/browse/CXF-8326
> Project: CXF
> Issue Type: Bug
> Components: Transports
> Affects Versions: 3.1.4
> Reporter: Alain Sellerin
> Priority: Major
>
> Hi,
> I'm doing a migration from CXF 2.4.6 to 3.1.4
>
> This code is working perfectly fine in 2.4.6:
> {noformat}
> SSLContext sslcontext = SSLContext.getInstance("TLSv1");
> ...
> TLSClientParameters tlsClientParameters = new TLSClientParameters();
> tlsClientParameters.setSSLSocketFactory(sslcontext.getSocketFactory());
> http.setTlsClientParameters(tlsClientParameters);{noformat}
> The ssl protocol version is respected when making the call (i-e TLSv1)
> With SSLContext.getInstance("TLSv1.1") the call is made with TLSv1.1
> With SSLContext.getInstance("TLSv1.2") the call is made with TLSv1.2
> All is fine.
>
> However, in 3.1.4, no matter the provided tls version it will always be
> TLSv1.2. The provided ssl version in SSLContext.getInstance("TLSv1") is just
> ignored.
> I checked with 3.2.7 and 2.7.18. It is failing as well.
>
> Thank you in advance for checking it.
> Regards
>
>
--
This message was sent by Atlassian Jira
(v8.3.4#803005)