Type:
Bug
Priority:
Major
Resolution:
Fixed
Affects Version/s:
2.0.2
Using Java 8 and MariaDB Connector/J 2.0.2-SNAPSHOT to connect to a MySQL 5.1.73 database using SSL does not appear to do server certificate verification.
The connection is created like this:
try (Connection c = DriverManager.getConnection(url, user, new String(password))) {
System.out.printf( "Connection class:%n%s%n" , c.getClass().getName());
}
where url is this (but with a different host name and DB name):
"jdbc:mariadb://db.example.com:3306/MYDB?useSSL=true"
No exception is thrown. The default Java TrustStore has not been altered. A dedicated TrustStore has not been specified with the trustStore and trustStorePassword URL options. And the trustServerCertificate URL option has not been specified, so it should default to false , and an exception should be thrown according to the "One way SSL authentication" section of Using TLS/SSL with MariaDB Connector/J which says:
If the trustServerCertificate option is not set, an exception "unable to find valid certification path to requested target" will be thrown.
The server certificate has been signed by a trusted CA (i.e., Entrust). I don't think this matters, but I'm mentioning it just in case. It would be awesome if Connector/J could verify the server certificate without requiring a dedicated TrustStore (i.e., verify the certificate chain all the way to the root that exists in the default Java TrustStore), but the above referenced documentation does not say it can do this, so my understanding is that it cannot and hence cannot explain what's happening here.
Diego Dupin
made changes -
2017-11-21 08:29
Field
Original Value
New Value
Component/s
documentation
[ 14210
]
Fix Version/s
N/A
[ 22125
]
Resolution
Fixed
[ 1
]
Status
Open
[ 1
]
Closed
[ 6
]
Sergei Golubchik
made changes -
2021-12-06 21:27
Workflow
MariaDB v3
[ 81052
]
MariaDB v4
[ 134989
]
{"report":{"fcp":963.9000005722046,"ttfb":231.70000076293945,"pageVisibility":"visible","entityId":61611,"key":"jira.project.issue.view-issue","isInitial":true,"threshold":1000,"elementTimings":{},"userDeviceMemory":8,"userDeviceProcessors":64,"apdex":0.5,"journeyId":"56e713af-dac7-4356-8df3-6e9889071e1e","navigationType":0,"readyForUser":1043.8000001907349,"redirectCount":0,"resourceLoadedEnd":1069.1000003814697,"resourceLoadedStart":237,"resourceTiming":[{"duration":161.9000005722046,"initiatorType":"link","name":"https://jira.mariadb.org/s/2c21342762a6a02add1c328bed317ffd-CDN/lu2cib/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/css/_super/batch.css","startTime":237,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":237,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":398.9000005722046,"responseStart":0,"secureConnectionStart":0},{"duration":161.9000005722046,"initiatorType":"link","name":"https://jira.mariadb.org/s/7ebd35e77e471bc30ff0eba799ebc151-CDN/lu2cib/820016/12ta74/494e4c556ecbb29f90a3d3b4f09cb99c/_/download/contextbatch/css/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.css?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true&whisper-enabled=true","startTime":237.30000019073486,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":237.30000019073486,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":399.20000076293945,"responseStart":0,"secureConnectionStart":0},{"duration":170.80000019073486,"initiatorType":"script","name":"https://jira.mariadb.org/s/0917945aaa57108d00c5076fea35e069-CDN/lu2cib/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/js/_super/batch.js?locale=en","startTime":237.5,"connectEnd":237.5,"connectStart":237.5,"domainLookupEnd":237.5,"domainLookupStart":237.5,"fetchStart":237.5,"redirectEnd":0,"redirectStart":0,"requestStart":237.5,"responseEnd":408.30000019073486,"responseStart":408.30000019073486,"secureConnectionStart":237.5},{"duration":225.0999994277954,"initiatorType":"script","name":"https://jira.mariadb.org/s/2d8175ec2fa4c816e8023260bd8c1786-CDN/lu2cib/820016/12ta74/494e4c556ecbb29f90a3d3b4f09cb99c/_/download/contextbatch/js/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.js?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&locale=en&slack-enabled=true&whisper-enabled=true","startTime":237.70000076293945,"connectEnd":237.70000076293945,"connectStart":237.70000076293945,"domainLookupEnd":237.70000076293945,"domainLookupStart":237.70000076293945,"fetchStart":237.70000076293945,"redirectEnd":0,"redirectStart":0,"requestStart":237.70000076293945,"responseEnd":462.80000019073486,"responseStart":462.80000019073486,"secureConnectionStart":237.70000076293945},{"duration":228.80000019073486,"initiatorType":"script","name":"https://jira.mariadb.org/s/a9324d6758d385eb45c462685ad88f1d-CDN/lu2cib/820016/12ta74/c92c0caa9a024ae85b0ebdbed7fb4bd7/_/download/contextbatch/js/atl.global,-_super/batch.js?locale=en","startTime":237.9000005722046,"connectEnd":237.9000005722046,"connectStart":237.9000005722046,"domainLookupEnd":237.9000005722046,"domainLookupStart":237.9000005722046,"fetchStart":237.9000005722046,"redirectEnd":0,"redirectStart":0,"requestStart":237.9000005722046,"responseEnd":466.70000076293945,"responseStart":466.70000076293945,"secureConnectionStart":237.9000005722046},{"duration":229.20000076293945,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-en/jira.webresources:calendar-en.js","startTime":238,"connectEnd":238,"connectStart":238,"domainLookupEnd":238,"domainLookupStart":238,"fetchStart":238,"redirectEnd":0,"redirectStart":0,"requestStart":238,"responseEnd":467.20000076293945,"responseStart":467.20000076293945,"secureConnectionStart":238},{"duration":229.19999980926514,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-localisation-moment/jira.webresources:calendar-localisation-moment.js","startTime":238.30000019073486,"connectEnd":238.30000019073486,"connectStart":238.30000019073486,"domainLookupEnd":238.30000019073486,"domainLookupStart":238.30000019073486,"fetchStart":238.30000019073486,"redirectEnd":0,"redirectStart":0,"requestStart":238.30000019073486,"responseEnd":467.5,"responseStart":467.5,"secureConnectionStart":238.30000019073486},{"duration":312.3999996185303,"initiatorType":"link","name":"https://jira.mariadb.org/s/b04b06a02d1959df322d9cded3aeecc1-CDN/lu2cib/820016/12ta74/a2ff6aa845ffc9a1d22fe23d9ee791fc/_/download/contextbatch/css/jira.global.look-and-feel,-_super/batch.css","startTime":238.4000005722046,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":238.4000005722046,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":550.8000001907349,"responseStart":0,"secureConnectionStart":0},{"duration":229.30000019073486,"initiatorType":"script","name":"https://jira.mariadb.org/rest/api/1.0/shortcuts/820016/47140b6e0a9bc2e4913da06536125810/shortcuts.js?context=issuenavigation&context=issueaction","startTime":238.60000038146973,"connectEnd":238.60000038146973,"connectStart":238.60000038146973,"domainLookupEnd":238.60000038146973,"domainLookupStart":238.60000038146973,"fetchStart":238.60000038146973,"redirectEnd":0,"redirectStart":0,"requestStart":238.60000038146973,"responseEnd":467.9000005722046,"responseStart":467.9000005722046,"secureConnectionStart":238.60000038146973},{"duration":312.19999980926514,"initiatorType":"link","name":"https://jira.mariadb.org/s/3ac36323ba5e4eb0af2aa7ac7211b4bb-CDN/lu2cib/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/css/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.css?jira.create.linked.issue=true","startTime":238.80000019073486,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":238.80000019073486,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":551,"responseStart":0,"secureConnectionStart":0},{"duration":229.4000005722046,"initiatorType":"script","name":"https://jira.mariadb.org/s/5d5e8fe91fbc506585e83ea3b62ccc4b-CDN/lu2cib/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/js/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.js?jira.create.linked.issue=true&locale=en","startTime":239,"connectEnd":239,"connectStart":239,"domainLookupEnd":239,"domainLookupStart":239,"fetchStart":239,"redirectEnd":0,"redirectStart":0,"requestStart":239,"responseEnd":468.4000005722046,"responseStart":468.4000005722046,"secureConnectionStart":239},{"duration":442.19999980926514,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-js/jira.webresources:bigpipe-js.js","startTime":244.20000076293945,"connectEnd":244.20000076293945,"connectStart":244.20000076293945,"domainLookupEnd":244.20000076293945,"domainLookupStart":244.20000076293945,"fetchStart":244.20000076293945,"redirectEnd":0,"redirectStart":0,"requestStart":244.20000076293945,"responseEnd":686.4000005722046,"responseStart":686.4000005722046,"secureConnectionStart":244.20000076293945},{"duration":763.4000005722046,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-init/jira.webresources:bigpipe-init.js","startTime":244.30000019073486,"connectEnd":244.30000019073486,"connectStart":244.30000019073486,"domainLookupEnd":244.30000019073486,"domainLookupStart":244.30000019073486,"fetchStart":244.30000019073486,"redirectEnd":0,"redirectStart":0,"requestStart":244.30000019073486,"responseEnd":1007.7000007629395,"responseStart":1007.6000003814697,"secureConnectionStart":244.30000019073486},{"duration":124.5,"initiatorType":"xmlhttprequest","name":"https://jira.mariadb.org/rest/webResources/1.0/resources","startTime":562.6000003814697,"connectEnd":562.6000003814697,"connectStart":562.6000003814697,"domainLookupEnd":562.6000003814697,"domainLookupStart":562.6000003814697,"fetchStart":562.6000003814697,"redirectEnd":0,"redirectStart":0,"requestStart":562.6000003814697,"responseEnd":687.1000003814697,"responseStart":687.1000003814697,"secureConnectionStart":562.6000003814697},{"duration":215.39999961853027,"initiatorType":"link","name":"https://jira.mariadb.org/s/d5715adaadd168a9002b108b2b039b50-CDN/lu2cib/820016/12ta74/be4b45e9cec53099498fa61c8b7acba4/_/download/contextbatch/css/jira.project.sidebar,-_super,-project.issue.navigator,-jira.general,-jira.browse.project,-jira.view.issue,-jira.global,-atl.general,-com.atlassian.jira.projects.sidebar.init/batch.css?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true&whisper-enabled=true","startTime":853.7000007629395,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":853.7000007629395,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":1069.1000003814697,"responseStart":0,"secureConnectionStart":0}],"fetchStart":1,"domainLookupStart":1,"domainLookupEnd":1,"connectStart":1,"connectEnd":1,"requestStart":82,"responseStart":232,"responseEnd":241,"domLoading":236,"domInteractive":1095,"domContentLoadedEventStart":1095,"domContentLoadedEventEnd":1135,"domComplete":1459,"loadEventStart":1459,"loadEventEnd":1459,"userAgent":"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)","marks":[{"name":"bigPipe.sidebar-id.start","time":1082.6000003814697},{"name":"bigPipe.sidebar-id.end","time":1083.4000005722046},{"name":"bigPipe.activity-panel-pipe-id.start","time":1083.5},{"name":"bigPipe.activity-panel-pipe-id.end","time":1085},{"name":"activityTabFullyLoaded","time":1151.6000003814697}],"measures":[],"correlationId":"21cc08877d5607","effectiveType":"4g","downlink":10,"rtt":0,"serverDuration":94,"dbReadsTimeInMs":10,"dbConnsTimeInMs":18,"applicationHash":"9d11dbea5f4be3d4cc21f03a88dd11d8c8687422","experiments":[]}}