[
https://issues.apache.org/jira/browse/DRILL-6581?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16539350#comment-16539350
]
ASF GitHub Bot commented on DRILL-6581:
---------------------------------------
sohami commented on a change in pull request #1366: [DRILL-6581] C++ Client SSL
Implementation Fixes/Improvements
URL: https://github.com/apache/drill/pull/1366#discussion_r201524731
##########
File path: contrib/native/client/src/clientlib/channel.hpp
##########
@@ -21,6 +21,17 @@
#include "drill/common.hpp"
#include "drill/drillClient.hpp"
#include "streamSocket.hpp"
+#include "errmsgs.hpp"
+
+#if defined(IS_SSL_ENABLED)
+#include <openssl/ssl.h>
+#endif
+
+namespace
+{
+// The error message to indicate certificate verification failure.
+#define DRILL_BOOST_SSL_CERT_VERIFY_FAILED "handshake: certificate verify
failed\0"
Review comment:
I don't think we can rely on this error string. Instead it would be good to
use something like below for decoding ssl errors.
https://stackoverflow.com/questions/9828066/how-to-decipher-a-boost-asio-ssl-error-code
----------------------------------------------------------------
This is an automated message from the Apache Git Service.
To respond to the message, please log on GitHub and use the
URL above to go to the specific comment.
For queries about this service, please contact Infrastructure at:
[email protected]
> Improve C++ Client SSL Implementation
> -------------------------------------
>
> Key: DRILL-6581
> URL: https://issues.apache.org/jira/browse/DRILL-6581
> Project: Apache Drill
> Issue Type: Improvement
> Components: Client - C++
> Affects Versions: 1.12.0
> Reporter: Rob Wu
> Assignee: Rob Wu
> Priority: Major
> Fix For: 1.14.0
>
>
> # Fix: Hostname verification doesnt function as expected: Host and port in
> the ssl hostname verification callback is always empty.
> # Fix: Certificate load verification exceptions are swallowed and not
> propagated.
> # Improvement: SSL V3 is not disabled.
> # Improvement: Hostname verification failure exception is the same as other
> certificate verification failures, we should separate them
> # Improvement: Create individual error messages to allow error handling of
> the application using the client and follows the standard of the rest of the
> errors
> # Improvement: Add SSL Hostname verification with zookeeper connection mode
> support
> # Added support for custom SSL CTX Options
--
This message was sent by Atlassian JIRA
(v7.6.3#76005)