JiriOndrusek opened a new issue, #9222:
URL: https://github.com/apache/camel-quarkus/issues/9222
### Bug description
On a FIPS enabled JVM, Testcontainers `MySQLContainer` waits for readiness
by opening a JDBC connection with `useSSL=false&allowPublicKeyRetrieval=true`.
Without TLS, `caching_sha2_password` requires the client to encrypt the
password with `RSA/ECB/OAEPWithSHA-1AndMGF1Padding`, which the
`SunPKCS11-NSS-FIPS` provider does not support. The MySQL container is healthy,
but it is never reported as started and the test fails after the startup
timeout.
Affected tests:
- `integration-tests/quartz-clustered`: uses the MySQL dev service, whose
container class extends `MySQLContainer`.
- `integration-test-groups/debezium/mysql`: `DebeziumMysqlTestResource`
creates `MySQLContainer` directly and also runs `initMysql.sql` over the same
JDBC connection.
```
Caused by: java.lang.IllegalStateException: Container is started, but cannot
be accessed by (JDBC URL: jdbc:mysql://localhost:32768/quarkus), please check
container logs
at
org.testcontainers.containers.JdbcDatabaseContainer.waitUntilContainerStarted(JdbcDatabaseContainer.java:210)
Caused by: java.sql.SQLException: Cannot find any provider supporting
RSA/ECB/OAEPWithSHA-1AndMGF1Padding
at
com.mysql.cj.protocol.ExportControlled.encryptWithRSAPublicKey(ExportControlled.java:268)
at
com.mysql.cj.protocol.a.authentication.Sha256PasswordPlugin.encryptPassword(Sha256PasswordPlugin.java:169)
at
com.mysql.cj.protocol.a.authentication.CachingSha2PasswordPlugin.nextAuthenticationStep(CachingSha2PasswordPlugin.java:134)
Caused by: javax.crypto.NoSuchPaddingException: Unsupported padding
OAEPWithSHA-1AndMGF1Padding
at
jdk.crypto.cryptoki/sun.security.pkcs11.P11RSACipher.engineSetPadding(P11RSACipher.java:137)
```
### Environment
RHEL 8.9 in FIPS mode, OpenJDK 17 (FIPS mode), Testcontainers 2.0.5, MySQL
Connector/J 9.7.0, image `mirror.gcr.io/mysql:9.5`.
### Proposed fix
Make the readiness probe connect over TLS. The password is then sent inside
the TLS channel and no RSA-OAEP step is needed. Regular (non-FIPS) runs stay
unchanged.
- quartz-clustered: `fips` Maven profile passing
`quarkus.datasource.devservices.properties.useSSL=true` to surefire and
failsafe (same pattern as the `fips` profiles in `jdbc/mysql`, `jdbc-grouped`
and `jasypt`).
- Debezium MySQL: `container.withUrlParam("useSSL", "true")` in
`DebeziumMysqlTestResource` when `FipsModeUtil.isFipsMode()`.
Related: quarkusio/quarkus#40526, #6062.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]