From f6563a904e25f77796f448e53d347b69ae7e1aa1 Mon Sep 17 00:00:00 2001 From: Balazs Meszaros Date: Mon, 5 Oct 2026 18:40:40 +0200 Subject: [PATCH] ZOOKEEPER-5054: Netty client should allow every supported TLS ciphers (addendum) Fixes testCreateSSLContext_ChaCha20Cipher unit test failure. It uses another approach to test the cipher suites in use. --- .../apache/zookeeper/common/X509UtilTest.java | 30 ++++++++++++------- 1 file changed, 19 insertions(+), 11 deletions(-) diff --git a/zookeeper-server/src/test/java/org/apache/zookeeper/common/X509UtilTest.java b/zookeeper-server/src/test/java/org/apache/zookeeper/common/X509UtilTest.java index 8dc988fed8d..1b4109c2ed4 100644 --- a/zookeeper-server/src/test/java/org/apache/zookeeper/common/X509UtilTest.java +++ b/zookeeper-server/src/test/java/org/apache/zookeeper/common/X509UtilTest.java @@ -37,6 +37,8 @@ import java.security.NoSuchAlgorithmException; import java.util.Arrays; import java.util.List; +import java.util.Set; +import java.util.TreeSet; import java.util.concurrent.Callable; import java.util.concurrent.CountDownLatch; import java.util.concurrent.ExecutionException; @@ -823,27 +825,33 @@ public void testCreateSSLContext_hostnameVerificationNoCustomTrustStore(X509KeyT @ParameterizedTest @MethodSource("data") - public void testCreateSSLContext_ChaCha20Cipher(X509KeyType caKeyType, + public void testCreateSSLContext_AllClientCiphers(X509KeyType caKeyType, X509KeyType certKeyType, String keyPassword, Integer paramIndex) throws Exception { init(caKeyType, certKeyType, keyPassword, paramIndex); - // TLS_CHACHA20_POLY1305_SHA256 cipher is a mandatory cipher suite on TLSv1.3, - // so a client with default configuration must support it. + // Netty has an own list of supported ciphers, which is a subset of + // JVM's available cipher suites. A client ssl engine must support every + // cipher which is supported by the JVM. - ZKConfig zkConfig = new ZKConfig(); - zkConfig.setProperty(x509Util.getSslEnabledProtocolsProperty(), "TLSv1.3"); + SSLContext defaultContext = SSLContext.getInstance("TLSv1.3"); + defaultContext.init(null, null, null); + + String[] defaultCipherArray = defaultContext.getSupportedSSLParameters().getCipherSuites(); + Set defaultCipherSet = new TreeSet<>(Arrays.asList(defaultCipherArray)); try (ClientX509Util clientX509Util = new ClientX509Util()) { - SslContext context = clientX509Util.createNettySslContextForClient(zkConfig); + ZKConfig config = new ZKConfig(); + config.setProperty(x509Util.getSslEnabledProtocolsProperty(), "TLSv1.3"); + + SslContext clientContext = clientX509Util.createNettySslContextForClient(config); UnpooledByteBufAllocator byteBufAllocator = new UnpooledByteBufAllocator(false); - SSLEngine engine = context.newEngine(byteBufAllocator); + SSLEngine engine = clientContext.newEngine(byteBufAllocator); - String[] enabledProtocols = engine.getEnabledProtocols(); - assertArrayEquals(new String[] { "TLSv1.3" }, enabledProtocols); + String[] clientCipherArray = engine.getEnabledCipherSuites(); + Set clientCipherSet = new TreeSet<>(Arrays.asList(clientCipherArray)); - List enabledCipherSuites = Arrays.asList(engine.getEnabledCipherSuites()); - assertTrue(enabledCipherSuites.contains("TLS_CHACHA20_POLY1305_SHA256")); + assertEquals(defaultCipherSet, clientCipherSet); } }