JiriOndrusek opened a new issue, #9222:
URL: https://github.com/apache/camel-quarkus/issues/9222

   ### Bug description
   
   On a FIPS enabled JVM, Testcontainers `MySQLContainer` waits for readiness 
by opening a JDBC connection with `useSSL=false&allowPublicKeyRetrieval=true`. 
Without TLS, `caching_sha2_password` requires the client to encrypt the 
password with `RSA/ECB/OAEPWithSHA-1AndMGF1Padding`, which the 
`SunPKCS11-NSS-FIPS` provider does not support. The MySQL container is healthy, 
but it is never reported as started and the test fails after the startup 
timeout.
   
   Affected tests:
   - `integration-tests/quartz-clustered`: uses the MySQL dev service, whose 
container class extends `MySQLContainer`.
   - `integration-test-groups/debezium/mysql`: `DebeziumMysqlTestResource` 
creates `MySQLContainer` directly and also runs `initMysql.sql` over the same 
JDBC connection.
   
   ```
   Caused by: java.lang.IllegalStateException: Container is started, but cannot 
be accessed by (JDBC URL: jdbc:mysql://localhost:32768/quarkus), please check 
container logs
       at 
org.testcontainers.containers.JdbcDatabaseContainer.waitUntilContainerStarted(JdbcDatabaseContainer.java:210)
   Caused by: java.sql.SQLException: Cannot find any provider supporting 
RSA/ECB/OAEPWithSHA-1AndMGF1Padding
       at 
com.mysql.cj.protocol.ExportControlled.encryptWithRSAPublicKey(ExportControlled.java:268)
       at 
com.mysql.cj.protocol.a.authentication.Sha256PasswordPlugin.encryptPassword(Sha256PasswordPlugin.java:169)
       at 
com.mysql.cj.protocol.a.authentication.CachingSha2PasswordPlugin.nextAuthenticationStep(CachingSha2PasswordPlugin.java:134)
   Caused by: javax.crypto.NoSuchPaddingException: Unsupported padding 
OAEPWithSHA-1AndMGF1Padding
       at 
jdk.crypto.cryptoki/sun.security.pkcs11.P11RSACipher.engineSetPadding(P11RSACipher.java:137)
   ```
   
   ### Environment
   
   RHEL 8.9 in FIPS mode, OpenJDK 17 (FIPS mode), Testcontainers 2.0.5, MySQL 
Connector/J 9.7.0, image `mirror.gcr.io/mysql:9.5`.
   
   ### Proposed fix
   
   Make the readiness probe connect over TLS. The password is then sent inside 
the TLS channel and no RSA-OAEP step is needed. Regular (non-FIPS) runs stay 
unchanged.
   
   - quartz-clustered: `fips` Maven profile passing 
`quarkus.datasource.devservices.properties.useSSL=true` to surefire and 
failsafe (same pattern as the `fips` profiles in `jdbc/mysql`, `jdbc-grouped` 
and `jasypt`).
   - Debezium MySQL: `container.withUrlParam("useSSL", "true")` in 
`DebeziumMysqlTestResource` when `FipsModeUtil.isFipsMode()`.
   
   Related: quarkusio/quarkus#40526, #6062.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to