This is an automated email from the ASF dual-hosted git repository.

markt-asf pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/tomcat.git

commit 8bd1106b638cd9adf77047364a88286385b43c55
Author: Mark Thomas <[email protected]>
AuthorDate: Thu Sep 24 16:34:36 2026 +0100

    Align with Tomcat Native 1.2.x
---
 .../apache/tomcat/jni/PreSharedKeySelector.java    | 18 +++++++++++---
 java/org/apache/tomcat/jni/SSLContext.java         | 28 +++++++++++++++-------
 2 files changed, 34 insertions(+), 12 deletions(-)

diff --git a/java/org/apache/tomcat/jni/PreSharedKeySelector.java 
b/java/org/apache/tomcat/jni/PreSharedKeySelector.java
index 2364fdfa10..478eab632e 100644
--- a/java/org/apache/tomcat/jni/PreSharedKeySelector.java
+++ b/java/org/apache/tomcat/jni/PreSharedKeySelector.java
@@ -18,8 +18,10 @@ package org.apache.tomcat.jni;
 
 /**
  * The interface for the Tomcat code that responds to the callback from the 
OpenSSL layer in Tomcat Native to allow
- * Tomcat to select a pre-shared key. It supports TLSv1.2 {@code 
SSL_CTX_set_psk_server_callback} and TLSv1.3
- * {@code SSL_CTX_set_psk_find_session_callback}.
+ * Tomcat to select a pre-shared key. It supports server-side TLSv1.2 {@code 
SSL_CTX_set_psk_server_callback},
+ * server-side TLSv1.3 {@code SSL_CTX_set_psk_find_session_callback}, 
client-side TLSv1.2
+ * {@code SSL_CTX_set_psk_client_callback} and client-side
+ * TLSv1.3 {@code SSL_CTX_set_psk_use_session_callback} call-backs.
  */
 public interface PreSharedKeySelector {
 
@@ -54,7 +56,7 @@ public interface PreSharedKeySelector {
 
 
     /**
-     * Selects the TLS1v2 identity and pre-shared key that the client will 
present to a server.
+     * Selects the TLSv1.2 identity and pre-shared key that the client will 
present to a server.
      *
      * @param ssl      the SSL instance
      * @param identity a single-element array that must be populated with the 
PSK identity
@@ -63,4 +65,14 @@ public interface PreSharedKeySelector {
      */
     byte[] selectClient(long ssl, String[] identity);
 
+    /**
+     * Selects the TLSv1.3 identity, pre-shared key and digest that the client 
will present to a server.
+     *
+     * @param ssl         the SSL instance
+     * @param identity    a single-element array that must be populated with 
the PSK identity
+     * @param cipherSuite a single-element array that must be populated with a 
IANA TLSv1.3 cipher suite identifier
+     *
+     * @return the pre-shared key (strictly the input to the KDF), or {@code 
null} if no key is available
+     */
+    byte[] selectClient(long ssl, String[] identity, int[] cipherSuite);
 }
diff --git a/java/org/apache/tomcat/jni/SSLContext.java 
b/java/org/apache/tomcat/jni/SSLContext.java
index 9a13006f93..74855b91d8 100644
--- a/java/org/apache/tomcat/jni/SSLContext.java
+++ b/java/org/apache/tomcat/jni/SSLContext.java
@@ -141,7 +141,7 @@ public final class SSLContext {
     public static native String[] getCiphers(long ctx);
 
     /**
-     * Set the TLSv1.2 and below ciphers available for negotiation in the TLS 
handshake.
+     * Set the TLSv1.2 and below ciphers available for negotiation the in TLS 
handshake.
      * <p>
      * This complex directive uses a colon-separated cipher-spec string 
consisting of OpenSSL cipher specifications to
      * configure the ciphers the client is permitted to negotiate in the TLS 
handshake phase.
@@ -156,7 +156,7 @@ public final class SSLContext {
     public static native boolean setCipherSuite(long ctx, String cipherList) 
throws Exception;
 
     /**
-     * Set the TLSv1.3 cipher suites available for negotiation in the TLS 
handshake.
+     * Set the TLSv1.3 cipher suites available for negotiation the in TLS 
handshake.
      * <p>
      * This uses a colon-separated list of TLSv1.3 cipher suite names in 
preference order.
      *
@@ -220,7 +220,7 @@ public final class SSLContext {
      * @param ctx      Server or Client context to use.
      * @param cert     Certificate file.
      * @param key      Private Key file to use if not in cert.
-     * @param password Certificate password. If null and certificate is 
encrypted, loading the certificate will fail.
+     * @param password Certificate password. If null and certificate is 
encrypted, password prompt will be displayed.
      * @param idx      Certificate index SSL_AIDX_RSA or SSL_AIDX_DSA.
      *
      * @return <code>true</code> if the operation was successful
@@ -276,7 +276,7 @@ public final class SSLContext {
      * @param ctx  Server or Client context to use.
      * @param mode The mode to set
      *
-     * @return the previous mode
+     * @return the value set
      */
     public static native long setSessionCacheMode(long ctx, long mode);
 
@@ -285,7 +285,7 @@ public final class SSLContext {
      *
      * @param ctx Server or Client context to use.
      *
-     * @return the current mode
+     * @return the value set
      */
     public static native long getSessionCacheMode(long ctx);
 
@@ -490,13 +490,23 @@ public final class SSLContext {
     public static native void setPskFindSessionCallback(long ctx, 
PreSharedKeySelector selector);
 
     /**
-     * Sets the TLSv1.2 client-side pre-shared key callback.
+     * Sets the TLSv1.2 client-side pre-shared key callback to a {@link 
PreSharedKeySelector} instance. This will call
+     * {@code SSL_CTX_set_psk_client_callback}.
      *
      * @param ctx      Client context to use
      * @param selector pre-shared key selector
      */
     public static native void setPskClientCallback(long ctx, 
PreSharedKeySelector selector);
 
+    /**
+     * Sets the TLSv1.3 client-side pre-shared key callback to a {@link 
PreSharedKeySelector} instance. This will call
+     * {@code SSL_CTX_set_psk_use_session_callback}.
+     *
+     * @param ctx      Client context to use
+     * @param selector pre-shared key selector
+     */
+    public static native void setPskUseSessionCallback(long ctx, 
PreSharedKeySelector selector);
+
     /**
      * Set application layer protocol for application layer protocol 
negotiation extension
      *
@@ -508,7 +518,7 @@ public final class SSLContext {
     public static native void setAlpnProtos(long ctx, String[] alpnProtos, int 
selectorFailureBehavior);
 
     /**
-     * Set the context within which sessions can be reused (server side only)
+     * Set the context within which session be reused (server side only)
      * http://www.openssl.org/docs/ssl/SSL_CTX_set_session_id_context.html
      *
      * @param ctx    Server context to use.
@@ -521,7 +531,7 @@ public final class SSLContext {
 
     /**
      * Set CertificateRaw <br>
-     * Use a keystore certificate and key to fill the BIO.
+     * Use keystore a certificate and key to fill the BIOP
      *
      * @param ctx        Server or Client context to use.
      * @param cert       Byte array with the certificate in DER encoding.
@@ -535,7 +545,7 @@ public final class SSLContext {
     /**
      * Add a certificate to the certificate chain. Certs should be added in 
order starting with the issuer of the host
      * certs and working up the certificate chain to the CA. <br>
-     * Use a keystore certificate chain to fill the BIO.
+     * Use keystore a certificate chain to fill the BIOP
      *
      * @param ctx  Server or Client context to use.
      * @param cert Byte array with the certificate in DER encoding.


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to