[ 
https://issues.apache.org/jira/browse/HADOOP-19997?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Jose Luis López updated HADOOP-19997:
-------------------------------------
    Assignee: Jose Luis López
      Status: Patch Available  (was: Open)

> TestSSLHttpServerMTLS.testUntrustedClientIsRejected fails intermittently with 
> SocketException instead of SSLHandshakeException
> ------------------------------------------------------------------------------------------------------------------------------
>
>                 Key: HADOOP-19997
>                 URL: https://issues.apache.org/jira/browse/HADOOP-19997
>             Project: Hadoop Common
>          Issue Type: Test
>          Components: common, test
>            Reporter: Jose Luis López
>            Assignee: Jose Luis López
>            Priority: Major
>              Labels: pull-request-available
>
> The test expects an {{SSLHandshakeException}}. The server rejects the client 
> certificate and drops the connection right away. That close races the 
> client's last handshake flight, and how the refusal reaches the client 
> depends on which side wins and on the TLS version:
> TLSv1.2: {{SSLHandshakeException}}.
> The close wins: the client fails writing its flight and gets a 
> {{SocketException}}.
> TLSv1.3: the client finishes its side of the handshake before the server has 
> verified the certificate. The failure then shows up on the request write as a 
> bare {{IOException}}.
> 7 of 25 runs fail. The server guarantees only that the request is refused, 
> not which exception the client sees. The fix calls {{getResponseCode()}} and 
> asserts that it throws an {{IOException}} other than {{ConnectException}}. 
> Unlike {{getInputStream()}}, {{getResponseCode()}} does not throw on an HTTP 
> error status, so an HTTP 403 or 500 sent over a handshake that should have 
> been refused still fails the test.
> Test-only change. Verified 30/30 under TLSv1.2 and TLSv1.3.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to