Skip to content

[CALCITE-7796] Avatica: hostname_verification=NONE has no effect with Apache HttpClient 5.6+ - #321

Open
amaechler wants to merge 1 commit into
apache:mainfrom
amaechler:hostname-verification-policy
Open

amaechler wants to merge 1 commit into
apache:mainfrom
amaechler:hostname-verification-policy

Conversation

@amaechler

Copy link
Copy Markdown

Fixes CALCITE-7796.

This PR sets the hostname verification policy explicitly using the three-argument constructor that exists since HttpClient 5.4:

  • NONE uses HostnameVerificationPolicy.CLIENT with NoopHostnameVerifier, so no hostname check runs.
  • STRICT (the default) uses HostnameVerificationPolicy.BOTH with the default verifier. This keeps the HttpClient verifier that ran before and additionally enables the JSSE check, which is what HttpClient 5.6 does by default.

I didn't update the httpclient5 in this PR, since the fix compiles and behaves the same on 5.5 (where there is no bug). I verified SslHostnameVerificationTest against both versions locally.

… Apache HttpClient 5.6+

With hostname_verification=NONE the remote driver is supposed to skip
TLS hostname verification. On Apache HttpClient 5.6 or newer it does
not: connections to a server whose certificate does not name the URL
host fail during the handshake with "No subject alternative DNS name
matching <host> found". The driver creates its DefaultClientTlsStrategy
with a HostnameVerifier but without a HostnameVerificationPolicy and
relies on the default. Up to HttpClient 5.5 that default was CLIENT, so
the NoopHostnameVerifier was the only check. Since 5.6 a strategy with
a verifier defaults to BOTH (and one without a verifier to BUILTIN);
either policy enables the JSSE endpoint identification during the
handshake, and the verifier has no influence on that check.

Set the policy explicitly: CLIENT with NoopHostnameVerifier for NONE,
and BOTH with the default verifier for STRICT, which matches the
current HttpClient default. The three-argument constructor exists since
HttpClient 5.4, so the fix also compiles against the current
dependency. The new SslHostnameVerificationTest passes on HttpClient 5.5
with and without the fix; it only fails on 5.6 or newer without it.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant