xdn-code opened a new pull request, #4422:
URL: https://github.com/apache/hertzbeat/pull/4422

   ## What's changed?
   
   Hi @PRCVSUSA, thank you for reporting this. Hi @orangeCatDeveloper, thank 
you as well for the clear root-cause analysis.
   
   The shared HTTP client only enabled `TLSv1`, `TLSv1.1`, `TLSv1.2`, and 
`SSLv3`. A TLS 1.3-only website then rejected the handshake with `Received 
fatal alert: protocol_version`.
   
   This change follows that analysis:
   
   - Enable `TLSv1.3` on `CommonHttpClient`
   - Drop `SSLv3`
   - Keep TLS 1.0–1.2 so older endpoints still work
   
   Please let me know if anything should be adjusted. Thanks again.
   
   ## Checklist
   - [x] I have read the [Contributing 
Guide](https://hertzbeat.apache.org/docs/community/code_style_and_quality_guide)
   - [x] I have written the necessary doc or comment.
   - [x] I have added the necessary unit tests and all cases have passed.
   
   ## Add or update API
   - [ ] I have added the necessary [e2e 
tests](https://github.com/apache/hertzbeat/tree/master/e2e) and all cases have 
passed.
   
   ## Test plan
   - [x] 
`CommonHttpClientSslTest.supportedSslProtocolsIncludeTls13AndExcludeSslv3`
   
   Fixes #2106
   
   
   Made with [Cursor](https://cursor.com)


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to