zrlw opened a new pull request, #16200:
URL: https://github.com/apache/dubbo/pull/16200

   ## What is the purpose of the change?
   1. Since Netty 4.2.11.Final, hostname checker was enabled by default, the 
checker will get expected host name from the session which created by client 
QuicSslEngine, but current dubbo create client QuicSslEngine without parameter 
```peerhost``` and the CertificateException will be thrown at 
```sun.security.util.HostnameChecker#match``` due to ```expectedName``` is null,
   ```
       public void match(String expectedName, X509Certificate cert,
                         boolean chainsToPublicCA) throws CertificateException {
           if (expectedName == null) {
               throw new CertificateException("Hostname or IP address is " +
                       "undefined.");
           }
           if (isIpAddress(expectedName)) {
              matchIP(expectedName, cert);
           } else {
              matchDNS(expectedName, cert, chainsToPublicCA);
           }
       }
   ```
   so we should create QuicSslEngine for client with parameter peer host to 
support hostname checker.
   
   2. The ```server.pem``` for ```TripleHttp3ProtocolTest``` changed by adding 
SAN (set ip address to 127.0.0.1) configuration to meet HostnameChecker match 
requirements.
   
   
   ## Checklist
   - [x] Make sure there is a 
[GitHub_issue](https://github.com/apache/dubbo/issues) field for the change.
   - [x] Write a pull request description that is detailed enough to understand 
what the pull request does, how, and why.
   - [x] Write necessary unit-test to verify your logic correction. If the new 
feature or significant change is committed, please remember to add sample in 
[dubbo samples](https://github.com/apache/dubbo-samples) project.
   - [x] Make sure gitHub actions can pass. [Why the workflow is failing and 
how to fix it?](../CONTRIBUTING.md)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to