yandrey321 commented on code in PR #11367:
URL: https://github.com/apache/ozone/pull/11367#discussion_r4145390888
##########
hadoop-hdds/framework/src/main/java/org/apache/hadoop/hdds/server/http/HttpServer2.java:
##########
@@ -549,7 +587,14 @@ private ServerConnector createHttpChannelConnector(
private ServerConnector createHttpsChannelConnector(
Server server, HttpConfiguration httpConfig) {
httpConfig.setSecureScheme(HTTPS_SCHEME);
- httpConfig.addCustomizer(new SecureRequestCustomizer());
+ // Jetty 12's SecureRequestCustomizer defaults to sniHostCheck=true,
which
+ // rejects every HTTPS request whose Host (or SNI) is not carried by the
+ // served certificate with a 400 "Invalid SNI" -- including requests to
an
+ // IP literal (which send no SNI) or to localhost/VIP/alias names absent
+ // from the keystore certificate. Jetty 9.4 only ran that check when the
+ // client's SNI matched a certificate, so such requests were served with
+ // the default certificate. Disable the check to preserve that behaviour.
+ httpConfig.addCustomizer(new SecureRequestCustomizer(false));
Review Comment:
I can pick up https://issues.apache.org/jira/browse/HDDS-9878 and add make
it configurable.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]