This is an automated email from the ASF dual-hosted git repository.

garydgregory pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/commons-net.git

commit 52c16bb0cc2d6d1ad05e7d8624865b6b9efaa64c
Author: Gary Gregory <[email protected]>
AuthorDate: Sat Jul 18 10:53:48 2026 -0700

    Refactor duplication.
---
 src/main/java/org/apache/commons/net/ftp/FTPSClient.java | 13 ++++---------
 1 file changed, 4 insertions(+), 9 deletions(-)

diff --git a/src/main/java/org/apache/commons/net/ftp/FTPSClient.java 
b/src/main/java/org/apache/commons/net/ftp/FTPSClient.java
index 15de27ff..0dce90b7 100644
--- a/src/main/java/org/apache/commons/net/ftp/FTPSClient.java
+++ b/src/main/java/org/apache/commons/net/ftp/FTPSClient.java
@@ -283,10 +283,8 @@ public class FTPSClient extends FTPClient {
         _prepareDataSocket_(socket);
         if (socket instanceof SSLSocket) {
             final SSLSocket sslSocket = (SSLSocket) socket;
-
             sslSocket.setUseClientMode(isClientMode);
             sslSocket.setEnableSessionCreation(isCreation);
-
             // server mode
             if (!isClientMode) {
                 sslSocket.setNeedClientAuth(isNeedClientAuth);
@@ -299,11 +297,8 @@ public class FTPSClient extends FTPClient {
                 sslSocket.setEnabledProtocols(protocols);
             }
             sslSocket.startHandshake();
-            if (isClientMode && hostnameVerifier != null && 
!hostnameVerifier.verify(_hostname_, sslSocket.getSession())) {
-                throw new SSLHandshakeException("Hostname doesn't match 
certificate");
-            }
+            verifyHostName(sslSocket);
         }
-
         return socket;
     }
 
@@ -1094,7 +1089,6 @@ public class FTPSClient extends FTPClient {
         final SSLSocket socket = createSSLSocket(_socket_);
         socket.setEnableSessionCreation(isCreation);
         socket.setUseClientMode(isClientMode);
-
         // client mode
         if (isClientMode) {
             if (tlsEndpointChecking) {
@@ -1104,7 +1098,6 @@ public class FTPSClient extends FTPClient {
             socket.setNeedClientAuth(isNeedClientAuth);
             socket.setWantClientAuth(isWantClientAuth);
         }
-
         if (protocols != null) {
             socket.setEnabledProtocols(protocols);
         }
@@ -1112,12 +1105,14 @@ public class FTPSClient extends FTPClient {
             socket.setEnabledCipherSuites(suites);
         }
         socket.startHandshake();
-
         // TODO the following setup appears to duplicate that in the super 
class methods
         _socket_ = socket;
         _controlInput_ = new BufferedReader(new 
InputStreamReader(socket.getInputStream(), getControlEncoding()));
         _controlOutput_ = new BufferedWriter(new 
OutputStreamWriter(socket.getOutputStream(), getControlEncoding()));
+        verifyHostName(socket);
+    }
 
+    private void verifyHostName(final SSLSocket socket) throws 
SSLHandshakeException {
         if (isClientMode && hostnameVerifier != null && 
!hostnameVerifier.verify(_hostname_, socket.getSession())) {
             throw new SSLHandshakeException("Hostname doesn't match 
certificate");
         }

Reply via email to