Uploaded image for project: 'Java Couchbase JVM Core'
  1. Java Couchbase JVM Core
  2. JVMCBC-468

Client should support reading trust store and keystore files from different locations

    XMLWordPrintable

Details

    • Improvement
    • Status: Resolved
    • Major
    • Resolution: Fixed
    • None
    • 1.5.2
    • None
    • None

    Description

      We are working to integrate x.509 certificate authentication into our environment. Currently the java client uses a single keystore file for both trust store (containing the root and intermediate ca certificates used to validate the server certificate) as well as the client certificate that is supplied to the server.

      This causes a number of problems in our environment. We maintain a "global" trust store file that is distributed to all our machines and contains the root and intermediate ca certs. However the per-client certificate is stored in a separate file and we have not found an acceptable way to merge these into a single file for compatibility with the couchbase client.

      Our security team has reviewed the couchbase client code and mentioned that they would prefer not to see the same keystore instance shared for the key store and trust store. Specifically they mentioned SSLEngineFactory.java lines 72-73

      https://github.com/couchbase/couchbase-jvm-core/blob/7dad8e449dd868d1a845c0c0570d5a5d8d8b4847/src/main/java/com/couchbase/client/core/endpoint/SSLEngineFactory.java#L73

      Can we have the java client accept two separate files instead?

      Attachments

        No reviews matched the request. Check your Options in the drop-down menu of this sections header.

        Activity

          bweir bweir added a comment -

          This works for me

          bweir bweir added a comment - This works for me
          daschl Michael Nitschinger added a comment - Updated http://review.couchbase.org/#/c/84200/
          bweir bweir added a comment -

          The latest review looks good. ship-it from our side

          bweir bweir added a comment - The latest review looks good. ship-it from our side

          We've merged it into master, will be in 2.5.2 (the november release)

          daschl Michael Nitschinger added a comment - We've merged it into master, will be in 2.5.2 (the november release)

          Thanks for raising it!

          daschl Michael Nitschinger added a comment - Thanks for raising it!

          People

            daschl Michael Nitschinger
            bweir bweir
            Votes:
            0 Vote for this issue
            Watchers:
            5 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Gerrit Reviews

                There are no open Gerrit changes

                PagerDuty