zrlw opened a new pull request, #16200:
URL: https://github.com/apache/dubbo/pull/16200
## What is the purpose of the change?
1. Since Netty 4.2.11.Final, hostname checker was enabled by default, the
checker will get expected host name from the session which created by client
QuicSslEngine, but current dubbo create client QuicSslEngine without parameter
```peerhost``` and the CertificateException will be thrown at
```sun.security.util.HostnameChecker#match``` due to ```expectedName``` is null,
```
public void match(String expectedName, X509Certificate cert,
boolean chainsToPublicCA) throws CertificateException {
if (expectedName == null) {
throw new CertificateException("Hostname or IP address is " +
"undefined.");
}
if (isIpAddress(expectedName)) {
matchIP(expectedName, cert);
} else {
matchDNS(expectedName, cert, chainsToPublicCA);
}
}
```
so we should create QuicSslEngine for client with parameter peer host to
support hostname checker.
2. The ```server.pem``` for ```TripleHttp3ProtocolTest``` changed by adding
SAN (set ip address to 127.0.0.1) configuration to meet HostnameChecker match
requirements.
## Checklist
- [x] Make sure there is a
[GitHub_issue](https://github.com/apache/dubbo/issues) field for the change.
- [x] Write a pull request description that is detailed enough to understand
what the pull request does, how, and why.
- [x] Write necessary unit-test to verify your logic correction. If the new
feature or significant change is committed, please remember to add sample in
[dubbo samples](https://github.com/apache/dubbo-samples) project.
- [x] Make sure gitHub actions can pass. [Why the workflow is failing and
how to fix it?](../CONTRIBUTING.md)
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]