nodece commented on code in PR #19483:
URL: https://github.com/apache/pulsar/pull/19483#discussion_r1107971242


##########
pulsar-common/src/main/java/org/apache/pulsar/common/util/keystoretls/KeyStoreSSLContext.java:
##########
@@ -159,8 +159,10 @@ public SSLContext createSSLContext() throws 
GeneralSecurityException, IOExceptio
                     : TrustManagerFactory.getInstance(tmfAlgorithm);
             KeyStore trustStore = KeyStore.getInstance(trustStoreTypeString);
             char[] passwordChars = trustStorePassword.toCharArray();
-            try (FileInputStream inputStream = new 
FileInputStream(trustStorePath)) {
-                trustStore.load(inputStream, passwordChars);
+            if (!Strings.isNullOrEmpty(trustStorePath)) {

Review Comment:
   We cannot pass the `null` to `TrustManagerFactory.init()`, I see the 
following code in conscrypt:
   ```
       @Override
       public TrustManager[] engineGetTrustManagers() {
           if (keyStore == null) {
               throw new IllegalStateException(
                       "TrustManagerFactory is not initialized");
           }
           return new TrustManager[] { new TrustManagerImpl(keyStore) };
       }
   ```
   
   The correct way is to call the `trustStore.load(null)` to init the 
truststore.
   
   



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to