[ 
https://issues.apache.org/jira/browse/CXF-8326?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17182406#comment-17182406
 ] 

Alain Sellerin edited comment on CXF-8326 at 8/22/20, 3:01 PM:
---------------------------------------------------------------

Hi,

I'm able to reproduce the problem in testAESIncludedTLSv11UsingSSLContext()

 

If instruction
{noformat}
final Greeter port = service.getHttpsPort();{noformat}
 

Is replaced with
{noformat}
final Greeter port = service.getPort(Greeter.class);{noformat}
The test is failing and negotiated ssl version is TLSv1.2 instead of TLSv1.1

Tested with
{noformat}
mvn test -Dtest=CipherSuitesTest#testAESIncludedTLSv11UsingSSLContext 
-Djavax.net.debug=ssl{noformat}
 


was (Author: asellerin):
Hi,

I'm able to reproduce the problem in testAESIncludedTLSv11UsingSSLContext()

 

If instruction
{noformat}
final Greeter port = service.getHttpsPort();{noformat}
 

Is replaced with
{noformat}
final Greeter port = service.getPort(Greeter.class);{noformat}
The test is failing and negotiated ssl version is TLSv1.2 instead of TLSv1.0

Tested with
{noformat}
mvn test -Dtest=CipherSuitesTest#testAESIncludedTLSv11UsingSSLContext 
-Djavax.net.debug=ssl{noformat}
 

> SSLContext protocol version is ignored
> --------------------------------------
>
>                 Key: CXF-8326
>                 URL: https://issues.apache.org/jira/browse/CXF-8326
>             Project: CXF
>          Issue Type: Bug
>          Components: Transports
>    Affects Versions: 3.1.4
>            Reporter: Alain Sellerin
>            Priority: Major
>
> Hi,
> I'm doing a migration from CXF 2.4.6 to 3.1.4
>  
> This code is working perfectly fine in 2.4.6:
> {noformat}
> SSLContext sslcontext = SSLContext.getInstance("TLSv1");
> ...
> TLSClientParameters tlsClientParameters = new TLSClientParameters();
> tlsClientParameters.setSSLSocketFactory(sslcontext.getSocketFactory());
> http.setTlsClientParameters(tlsClientParameters);{noformat}
> The ssl protocol version is respected when making the call (i-e TLSv1)
> With SSLContext.getInstance("TLSv1.1") the call is made with TLSv1.1
> With SSLContext.getInstance("TLSv1.2") the call is made with TLSv1.2
> All is fine.
>  
> However, in 3.1.4, no matter the provided tls version it will always be 
> TLSv1.2. The provided ssl version in SSLContext.getInstance("TLSv1") is just 
> ignored. 
> I checked with 3.2.7 and 2.7.18. It is failing as well.
>  
> Thank you in advance for checking it.
> Regards
>  
>  



--
This message was sent by Atlassian Jira
(v8.3.4#803005)

Reply via email to