Uploaded image for project: 'MariaDB Connector/J'
  1. MariaDB Connector/J
  2. CONJ-1363

Rely on native TLS 1.3 and modern JSSE for the TLS-by-default work

    XMLWordPrintable

Details

    • New Feature
    • Status: Closed (View Workflow)
    • Major
    • Resolution: Fixed
    • None
    • 4.0.0
    • SSL
    • None

    Description

      TlsSocketPlugin still requests SSLContext.getInstance("TLS") and ConnectionHelper documents TLS 1.1 era defaults. With Java 17, TLS 1.3 and the current JSSE cipher defaults are always present.

      • Make TLS 1.3 and 1.2 the default enabledSslProtocolSuites and remove the workarounds for older suites.
      • Review the enabledSslCipherSuites defaults and sslMode handling against JDK 17 behaviour, including hostname verification through SSLParameters.setEndpointIdentificationAlgorithm.
      • Update the TLS tests and the security documentation accordingly.

      Attachments

        Activity

          People

            diego dupin Diego Dupin
            diego dupin Diego Dupin
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Git Integration

                Error rendering 'com.xiplink.jira.git.jira_git_plugin:git-issue-webpanel'. Please contact your Jira administrators.