apache/dubbo

NettyConnectionClient And NettyClient support SslContext rebuild when reconnect

オープン

#13,225 opened on 2023/10/17

 (0 件のコメント) (0 件のリアクション) (0 人の担当者)Java (26,453 件のフォーク)batch import
component/sdkhelp wantedtype/proposal

Repository metrics

Stars
 (41,524 個のスター)
PR merge metrics
 (PR metrics pending)

説明

  • I have searched the issues of this repository and believe that this is not a duplicate.
  • I have searched the release notes of this repository and believe that this is not a duplicate.

Describe the feature

org.apache.dubbo.remoting.transport.netty4.ExtNettyConnectionClient#initBootstrap org.apache.dubbo.remoting.transport.netty4.NettyClient#initBootstrap SslContext均在ChannelInitializer外部构建初始化, 在开启MTls认证时, 客户端证书可能因为轮换或者禁用发生变更, 此时重新建连 是无法使用最新的证书进行认证的. 建议将SslContext sslContext = SslContexts.buildClientSslContext(getUrl()); 迁移到ChannelInitializer内部.

コントリビューターガイド