[ 
https://issues.apache.org/jira/browse/IMPALA-15393?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18117964#comment-18117964
 ] 

Csaba Ringhofer commented on IMPALA-15393:
------------------------------------------

https://gerrit.cloudera.org/#/c/24912/

> Thrift 0.24 bump broken some ssl tests
> --------------------------------------
>
>                 Key: IMPALA-15393
>                 URL: https://issues.apache.org/jira/browse/IMPALA-15393
>             Project: IMPALA
>          Issue Type: Bug
>          Components: Backend
>            Reporter: Csaba Ringhofer
>            Assignee: Csaba Ringhofer
>            Priority: Critical
>
> These pass on Ubuntu 22.04 but fail on RHEL 8.6: 
> SslTest.MatchedTlsCiphersuites
> SslTest.OverlappingMatchedTlsCiphersuites
> Msg:
> {code}
> Expected: { ssl_client.iface()->RegisterSubscriber( resp, 
> TRegisterSubscriberRequest(), &send_done); } doesn't throw an exception.
>   Actual: it throws apache::thrift::transport::TSSLException with description 
> "SSL_connect: sslv3 alert handshake failure (SSL_error_code = 1)".
> {code}
> -The cause is a test bug, not a product issue. The Thrift bump brings new ssl 
> context initialization logic, the leads to allowed ssl versions with gaps in 
> these tests:-
> UPDATA: realized that this actually affects production, allowing lowering to 
> tls 1.2 when the system default is 1.3 - this was not possible with old logic
> tls1, tls1.1, tls1.3 <- tls .1.2 is explicitly disabled for the test
> The whole in the allowed versions leads to not finding any cyphers in some 
> environments.
> The fix is to not allow tls1/1.1 in the tests, which was never the intention 
> of them.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to