From d858490f8afba9e3e282f89fceb9cc7279549f4c Mon Sep 17 00:00:00 2001 From: zstan Date: Fri, 11 Sep 2026 12:09:52 +0300 Subject: [PATCH 01/10] IGNITE-29051 Several tests from JdbcThinConnectionSSLTest are failed locally --- .../jdbc/thin/JdbcThinConnectionSSLTest.java | 68 +++++++++++++++---- 1 file changed, 54 insertions(+), 14 deletions(-) diff --git a/modules/clients/src/test/java/org/apache/ignite/jdbc/thin/JdbcThinConnectionSSLTest.java b/modules/clients/src/test/java/org/apache/ignite/jdbc/thin/JdbcThinConnectionSSLTest.java index 3e2bb1d41b22f..cb56c05b01bf7 100644 --- a/modules/clients/src/test/java/org/apache/ignite/jdbc/thin/JdbcThinConnectionSSLTest.java +++ b/modules/clients/src/test/java/org/apache/ignite/jdbc/thin/JdbcThinConnectionSSLTest.java @@ -23,6 +23,9 @@ import java.sql.ResultSet; import java.sql.SQLException; import java.sql.Statement; +import java.util.Arrays; +import java.util.HashSet; +import java.util.Set; import java.util.concurrent.Callable; import javax.cache.configuration.Factory; import javax.net.ssl.SSLContext; @@ -333,15 +336,18 @@ public void testCustomCiphersOnServer() throws Exception { */ @Test public void testDisabledCustomCipher() throws Exception { + Set disabledSuites = disabledByDefaultCipherSuites(); + String disabledSuite = disabledSuites.iterator().next(); + setSslCtxFactoryToCli = true; - supportedCiphers = new String[] {"TLS_RSA_WITH_NULL_SHA256" /* Disabled by default */}; + supportedCiphers = new String[] {disabledSuite /* Disabled by default */}; sslCtxFactory = getTestSslContextFactory(); startGrids(1); try { // Explicit supported ciphers. try (Connection conn = DriverManager.getConnection("jdbc:ignite:thin://127.0.0.1/?sslMode=require" + - "&sslCipherSuites=TLS_RSA_WITH_NULL_SHA256" + + "&sslCipherSuites=" + disabledSuite + "&sslTrustAll=true" + "&sslClientCertificateKeyStoreUrl=" + CLI_KEY_STORE_PATH + "&sslClientCertificateKeyStorePassword=123456" + @@ -350,9 +356,14 @@ public void testDisabledCustomCipher() throws Exception { checkConnection(conn); } - // Default ciphers. + String completellyDisabledSuite = "TLS_RSA_WITH_NULL_SHA256"; + + assertFalse(supportedCipherSuites().contains(completellyDisabledSuite)); + + // Java 17+, the cipher suite TLS_RSA_WITH_NULL_SHA256 is completely disabled by default. GridTestUtils.assertThrows(log, () -> { return DriverManager.getConnection("jdbc:ignite:thin://127.0.0.1/?sslMode=require" + + "&sslCipherSuites=" + completellyDisabledSuite + "&sslClientCertificateKeyStoreUrl=" + CLI_KEY_STORE_PATH + "&sslClientCertificateKeyStorePassword=123456" + "&sslTrustCertificateKeyStoreUrl=" + TRUST_KEY_STORE_PATH + @@ -372,10 +383,12 @@ public void testDisabledCustomCipher() throws Exception { */ @Test public void testUnsupportedCustomCipher() throws Exception { + String disabledSuite = disabledByDefaultCipherSuites().iterator().next(); + setSslCtxFactoryToCli = true; supportedCiphers = new String[] { - "TLS_RSA_WITH_NULL_SHA256" /* Disabled by default */, - "TLS_ECDH_anon_WITH_3DES_EDE_CBC_SHA" /* With disabled protocol*/}; + disabledSuite /* Supported by JDK */, + "TLS_ECDH_anon_WITH_3DES_EDE_CBC_SHA" /* Anonymous cipher is disabled by default */}; sslCtxFactory = getTestSslContextFactory(); startGrids(1); @@ -393,7 +406,7 @@ public void testUnsupportedCustomCipher() throws Exception { // Supported cipher. try (Connection conn = DriverManager.getConnection("jdbc:ignite:thin://127.0.0.1/?sslMode=require" + - "&sslCipherSuites=TLS_RSA_WITH_NULL_SHA256" + + "&sslCipherSuites=" + disabledSuite + "&sslTrustAll=true" + "&sslClientCertificateKeyStoreUrl=" + CLI_KEY_STORE_PATH + "&sslClientCertificateKeyStorePassword=123456" + @@ -403,14 +416,13 @@ public void testUnsupportedCustomCipher() throws Exception { } // Default ciphers. - GridTestUtils.assertThrows(log, () -> { - return DriverManager.getConnection("jdbc:ignite:thin://127.0.0.1/?sslMode=require" + - "&sslClientCertificateKeyStoreUrl=" + CLI_KEY_STORE_PATH + - "&sslClientCertificateKeyStorePassword=123456" + - "&sslTrustCertificateKeyStoreUrl=" + TRUST_KEY_STORE_PATH + - "&sslTrustCertificateKeyStorePassword=123456"); - }, SQLException.class, "Failed to SSL connect to server"); - + try (Connection conn = DriverManager.getConnection("jdbc:ignite:thin://127.0.0.1/?sslMode=require" + + "&sslClientCertificateKeyStoreUrl=" + CLI_KEY_STORE_PATH + + "&sslClientCertificateKeyStorePassword=123456" + + "&sslTrustCertificateKeyStoreUrl=" + TRUST_KEY_STORE_PATH + + "&sslTrustCertificateKeyStorePassword=123456")) { + checkConnection(conn); + } } finally { stopAllGrids(); @@ -723,4 +735,32 @@ public static class TestSSLFactory implements Factory { return getTestSslContextFactory().create().getSocketFactory(); } } + + /** */ + private Set supportedCipherSuites() throws Exception { + // Initialize a standard SSL/TLS context to load all protocols + SSLContext ctx = SSLContext.getInstance("TLS"); + ctx.init(null, null, null); + SSLSocketFactory factory = ctx.getSocketFactory(); + + // Retrieve all available cipher suites + return Set.of(factory.getSupportedCipherSuites()); + } + + /** */ + private Set disabledByDefaultCipherSuites() throws Exception { + SSLContext ctx = SSLContext.getInstance("TLSv1.2"); + ctx.init(null, null, null); + SSLSocketFactory factory = ctx.getSocketFactory(); + + Set dfltCiphersSuites = Set.of(factory.getDefaultCipherSuites()); + Set supportedCiphersSuites = new HashSet<>(Arrays.stream(factory.getSupportedCipherSuites()).toList()); + + // Fulter supported, but NOT in the default active list. + supportedCiphersSuites.removeAll(dfltCiphersSuites); + + assertFalse("No one disabled by default suite found", supportedCiphersSuites.isEmpty()); + + return supportedCiphersSuites; + } } From 1a1858b615506bd37633291b2da9f27198f5ab4a Mon Sep 17 00:00:00 2001 From: zstan Date: Fri, 11 Sep 2026 14:53:46 +0300 Subject: [PATCH 02/10] debug --- .../apache/ignite/jdbc/thin/JdbcThinConnectionSSLTest.java | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/modules/clients/src/test/java/org/apache/ignite/jdbc/thin/JdbcThinConnectionSSLTest.java b/modules/clients/src/test/java/org/apache/ignite/jdbc/thin/JdbcThinConnectionSSLTest.java index cb56c05b01bf7..1d3c8226742ac 100644 --- a/modules/clients/src/test/java/org/apache/ignite/jdbc/thin/JdbcThinConnectionSSLTest.java +++ b/modules/clients/src/test/java/org/apache/ignite/jdbc/thin/JdbcThinConnectionSSLTest.java @@ -339,6 +339,10 @@ public void testDisabledCustomCipher() throws Exception { Set disabledSuites = disabledByDefaultCipherSuites(); String disabledSuite = disabledSuites.iterator().next(); + System.out.println("Run test with suite: " + disabledSuite); + + System.err.println("!!!: " + disabledSuites); + setSslCtxFactoryToCli = true; supportedCiphers = new String[] {disabledSuite /* Disabled by default */}; sslCtxFactory = getTestSslContextFactory(); From 956e0fca99e1de619b865723b216f6b2aab78fd4 Mon Sep 17 00:00:00 2001 From: zstan Date: Fri, 11 Sep 2026 15:23:16 +0300 Subject: [PATCH 03/10] debug2 --- .../org/apache/ignite/jdbc/thin/JdbcThinConnectionSSLTest.java | 3 +++ 1 file changed, 3 insertions(+) diff --git a/modules/clients/src/test/java/org/apache/ignite/jdbc/thin/JdbcThinConnectionSSLTest.java b/modules/clients/src/test/java/org/apache/ignite/jdbc/thin/JdbcThinConnectionSSLTest.java index 1d3c8226742ac..300750cc55a0c 100644 --- a/modules/clients/src/test/java/org/apache/ignite/jdbc/thin/JdbcThinConnectionSSLTest.java +++ b/modules/clients/src/test/java/org/apache/ignite/jdbc/thin/JdbcThinConnectionSSLTest.java @@ -763,6 +763,9 @@ private Set disabledByDefaultCipherSuites() throws Exception { // Fulter supported, but NOT in the default active list. supportedCiphersSuites.removeAll(dfltCiphersSuites); + // Current TC settings. + supportedCiphersSuites.removeIf(s -> s.contains("_anon_")); + assertFalse("No one disabled by default suite found", supportedCiphersSuites.isEmpty()); return supportedCiphersSuites; From 9b7f131215729df890c58574a2c6a5ed37ab9be7 Mon Sep 17 00:00:00 2001 From: zstan Date: Fri, 11 Sep 2026 15:58:21 +0300 Subject: [PATCH 04/10] debug --- .../apache/ignite/jdbc/thin/JdbcThinConnectionSSLTest.java | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/modules/clients/src/test/java/org/apache/ignite/jdbc/thin/JdbcThinConnectionSSLTest.java b/modules/clients/src/test/java/org/apache/ignite/jdbc/thin/JdbcThinConnectionSSLTest.java index 300750cc55a0c..d1a42c9ca174d 100644 --- a/modules/clients/src/test/java/org/apache/ignite/jdbc/thin/JdbcThinConnectionSSLTest.java +++ b/modules/clients/src/test/java/org/apache/ignite/jdbc/thin/JdbcThinConnectionSSLTest.java @@ -360,14 +360,14 @@ public void testDisabledCustomCipher() throws Exception { checkConnection(conn); } - String completellyDisabledSuite = "TLS_RSA_WITH_NULL_SHA256"; + String completelyDisabledSuite = "TLS_DH_anon_WITH_AES_256_CBC_SHA"; - assertFalse(supportedCipherSuites().contains(completellyDisabledSuite)); + assertFalse(supportedCipherSuites().contains(completelyDisabledSuite)); // Java 17+, the cipher suite TLS_RSA_WITH_NULL_SHA256 is completely disabled by default. GridTestUtils.assertThrows(log, () -> { return DriverManager.getConnection("jdbc:ignite:thin://127.0.0.1/?sslMode=require" + - "&sslCipherSuites=" + completellyDisabledSuite + + "&sslCipherSuites=" + completelyDisabledSuite + "&sslClientCertificateKeyStoreUrl=" + CLI_KEY_STORE_PATH + "&sslClientCertificateKeyStorePassword=123456" + "&sslTrustCertificateKeyStoreUrl=" + TRUST_KEY_STORE_PATH + From b6fc30a21ddcf070d18529c01d16ecb3d1c4ac66 Mon Sep 17 00:00:00 2001 From: zstan Date: Fri, 11 Sep 2026 16:53:11 +0300 Subject: [PATCH 05/10] debug --- .../jdbc/thin/JdbcThinConnectionSSLTest.java | 21 +++++++++++++++---- 1 file changed, 17 insertions(+), 4 deletions(-) diff --git a/modules/clients/src/test/java/org/apache/ignite/jdbc/thin/JdbcThinConnectionSSLTest.java b/modules/clients/src/test/java/org/apache/ignite/jdbc/thin/JdbcThinConnectionSSLTest.java index d1a42c9ca174d..aa5f89bb6be39 100644 --- a/modules/clients/src/test/java/org/apache/ignite/jdbc/thin/JdbcThinConnectionSSLTest.java +++ b/modules/clients/src/test/java/org/apache/ignite/jdbc/thin/JdbcThinConnectionSSLTest.java @@ -339,9 +339,7 @@ public void testDisabledCustomCipher() throws Exception { Set disabledSuites = disabledByDefaultCipherSuites(); String disabledSuite = disabledSuites.iterator().next(); - System.out.println("Run test with suite: " + disabledSuite); - - System.err.println("!!!: " + disabledSuites); + System.out.println("Run test with cipher suite: " + disabledSuite); setSslCtxFactoryToCli = true; supportedCiphers = new String[] {disabledSuite /* Disabled by default */}; @@ -360,7 +358,22 @@ public void testDisabledCustomCipher() throws Exception { checkConnection(conn); } - String completelyDisabledSuite = "TLS_DH_anon_WITH_AES_256_CBC_SHA"; + /* completely disabled jdk 17+ + DES (56-bit): + TLS_RSA_WITH_DES_CBC_SHA, TLS_DHE_RSA_WITH_DES_CBC_SHA, + TLS_DHE_DSS_WITH_DES_CBC_SHA, TLS_ECDHE_ECDSA_WITH_DES_CBC_SHA, + TLS_ECDHE_RSA_WITH_DES_CBC_SHA, TLS_ECDHE_PSK_WITH_DES_CBC_SHA, + TLS_ECDH_ECDSA_WITH_DES_CBC_SHA, TLS_ECDH_RSA_WITH_DES_CBC_SHA, + TLS_ECDH_anon_WITH_DES_CBC_SHA + + 3DES/DESede: + TLS_RSA_WITH_3DES_EDE_CBC_SHA, TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA, + TLS_DHE_DSS_WITH_3DES_EDE_CBC_SHA, + TLS_ECDHE_ECDSA_WITH_3DES_EDE_CBC_SHA, TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA, + TLS_ECDHE_PSK_WITH_3DES_EDE_CBC_SHA, TLS_ECDH_ECDSA_WITH_3DES_EDE_CBC_SHA, + TLS_ECDH_RSA_WITH_3DES_EDE_CBC_SHA, TLS_ECDH_anon_WITH_3DES_EDE_CBC_SHA*/ + + String completelyDisabledSuite = "TLS_RSA_WITH_DES_CBC_SHA"; assertFalse(supportedCipherSuites().contains(completelyDisabledSuite)); From 38c4def8070ed4ebad8e66f1410b88645d560970 Mon Sep 17 00:00:00 2001 From: zstan Date: Fri, 11 Sep 2026 16:58:30 +0300 Subject: [PATCH 06/10] fix --- .../jdbc/thin/JdbcThinConnectionSSLTest.java | 29 ++++++++++--------- 1 file changed, 15 insertions(+), 14 deletions(-) diff --git a/modules/clients/src/test/java/org/apache/ignite/jdbc/thin/JdbcThinConnectionSSLTest.java b/modules/clients/src/test/java/org/apache/ignite/jdbc/thin/JdbcThinConnectionSSLTest.java index aa5f89bb6be39..d10d4e724dc2d 100644 --- a/modules/clients/src/test/java/org/apache/ignite/jdbc/thin/JdbcThinConnectionSSLTest.java +++ b/modules/clients/src/test/java/org/apache/ignite/jdbc/thin/JdbcThinConnectionSSLTest.java @@ -358,20 +358,21 @@ public void testDisabledCustomCipher() throws Exception { checkConnection(conn); } - /* completely disabled jdk 17+ - DES (56-bit): - TLS_RSA_WITH_DES_CBC_SHA, TLS_DHE_RSA_WITH_DES_CBC_SHA, - TLS_DHE_DSS_WITH_DES_CBC_SHA, TLS_ECDHE_ECDSA_WITH_DES_CBC_SHA, - TLS_ECDHE_RSA_WITH_DES_CBC_SHA, TLS_ECDHE_PSK_WITH_DES_CBC_SHA, - TLS_ECDH_ECDSA_WITH_DES_CBC_SHA, TLS_ECDH_RSA_WITH_DES_CBC_SHA, - TLS_ECDH_anon_WITH_DES_CBC_SHA - - 3DES/DESede: - TLS_RSA_WITH_3DES_EDE_CBC_SHA, TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA, - TLS_DHE_DSS_WITH_3DES_EDE_CBC_SHA, - TLS_ECDHE_ECDSA_WITH_3DES_EDE_CBC_SHA, TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA, - TLS_ECDHE_PSK_WITH_3DES_EDE_CBC_SHA, TLS_ECDH_ECDSA_WITH_3DES_EDE_CBC_SHA, - TLS_ECDH_RSA_WITH_3DES_EDE_CBC_SHA, TLS_ECDH_anon_WITH_3DES_EDE_CBC_SHA*/ + //completely disabled jdk 17+ + + //DES (56-bit): + //TLS_RSA_WITH_DES_CBC_SHA, TLS_DHE_RSA_WITH_DES_CBC_SHA, + // TLS_DHE_DSS_WITH_DES_CBC_SHA, TLS_ECDHE_ECDSA_WITH_DES_CBC_SHA, + // TLS_ECDHE_RSA_WITH_DES_CBC_SHA, TLS_ECDHE_PSK_WITH_DES_CBC_SHA, + // TLS_ECDH_ECDSA_WITH_DES_CBC_SHA, TLS_ECDH_RSA_WITH_DES_CBC_SHA, + // TLS_ECDH_anon_WITH_DES_CBC_SHA + + //3DES/DESede: + //TLS_RSA_WITH_3DES_EDE_CBC_SHA, TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA, + // TLS_DHE_DSS_WITH_3DES_EDE_CBC_SHA, + // TLS_ECDHE_ECDSA_WITH_3DES_EDE_CBC_SHA, TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA, + // TLS_ECDHE_PSK_WITH_3DES_EDE_CBC_SHA, TLS_ECDH_ECDSA_WITH_3DES_EDE_CBC_SHA, + // TLS_ECDH_RSA_WITH_3DES_EDE_CBC_SHA, TLS_ECDH_anon_WITH_3DES_EDE_CBC_SHA String completelyDisabledSuite = "TLS_RSA_WITH_DES_CBC_SHA"; From 478d573f51715081da7ebbc1750b485b0b7dcc4e Mon Sep 17 00:00:00 2001 From: zstan Date: Fri, 11 Sep 2026 18:40:38 +0300 Subject: [PATCH 07/10] fix --- .../org/apache/ignite/jdbc/thin/JdbcThinConnectionSSLTest.java | 2 ++ 1 file changed, 2 insertions(+) diff --git a/modules/clients/src/test/java/org/apache/ignite/jdbc/thin/JdbcThinConnectionSSLTest.java b/modules/clients/src/test/java/org/apache/ignite/jdbc/thin/JdbcThinConnectionSSLTest.java index d10d4e724dc2d..511ed3148cb7a 100644 --- a/modules/clients/src/test/java/org/apache/ignite/jdbc/thin/JdbcThinConnectionSSLTest.java +++ b/modules/clients/src/test/java/org/apache/ignite/jdbc/thin/JdbcThinConnectionSSLTest.java @@ -433,6 +433,8 @@ public void testUnsupportedCustomCipher() throws Exception { checkConnection(conn); } + // JDK 17+ removes RC4, DES, 3DES, anon from getSupportedCipherSuites() entirely + // (not just disabled by default). All non-anon TLS 1.2 suites are enabled by default. // Default ciphers. try (Connection conn = DriverManager.getConnection("jdbc:ignite:thin://127.0.0.1/?sslMode=require" + "&sslClientCertificateKeyStoreUrl=" + CLI_KEY_STORE_PATH + From 06dc68e9796cecfec8149fd54e6592da5d162378 Mon Sep 17 00:00:00 2001 From: zstan Date: Fri, 11 Sep 2026 19:59:46 +0300 Subject: [PATCH 08/10] fix --- .../jdbc/thin/JdbcThinConnectionSSLTest.java | 17 ++++++++--------- 1 file changed, 8 insertions(+), 9 deletions(-) diff --git a/modules/clients/src/test/java/org/apache/ignite/jdbc/thin/JdbcThinConnectionSSLTest.java b/modules/clients/src/test/java/org/apache/ignite/jdbc/thin/JdbcThinConnectionSSLTest.java index 511ed3148cb7a..1bc993211b066 100644 --- a/modules/clients/src/test/java/org/apache/ignite/jdbc/thin/JdbcThinConnectionSSLTest.java +++ b/modules/clients/src/test/java/org/apache/ignite/jdbc/thin/JdbcThinConnectionSSLTest.java @@ -433,16 +433,15 @@ public void testUnsupportedCustomCipher() throws Exception { checkConnection(conn); } - // JDK 17+ removes RC4, DES, 3DES, anon from getSupportedCipherSuites() entirely - // (not just disabled by default). All non-anon TLS 1.2 suites are enabled by default. // Default ciphers. - try (Connection conn = DriverManager.getConnection("jdbc:ignite:thin://127.0.0.1/?sslMode=require" + - "&sslClientCertificateKeyStoreUrl=" + CLI_KEY_STORE_PATH + - "&sslClientCertificateKeyStorePassword=123456" + - "&sslTrustCertificateKeyStoreUrl=" + TRUST_KEY_STORE_PATH + - "&sslTrustCertificateKeyStorePassword=123456")) { - checkConnection(conn); - } + // Behavior can be different for local and TC runs due to different: java.security settings + GridTestUtils.assertThrows(log, () -> { + return DriverManager.getConnection("jdbc:ignite:thin://127.0.0.1/?sslMode=require" + + "&sslClientCertificateKeyStoreUrl=" + CLI_KEY_STORE_PATH + + "&sslClientCertificateKeyStorePassword=123456" + + "&sslTrustCertificateKeyStoreUrl=" + TRUST_KEY_STORE_PATH + + "&sslTrustCertificateKeyStorePassword=123456"); + }, SQLException.class, "Failed to SSL connect to server"); } finally { stopAllGrids(); From 8206da97bf5240041b7f329917bdcfa28cf4f1c2 Mon Sep 17 00:00:00 2001 From: zstan Date: Mon, 14 Sep 2026 15:59:04 +0300 Subject: [PATCH 09/10] fix after review --- .../jdbc/thin/JdbcThinConnectionSSLTest.java | 20 +++++++++++-------- 1 file changed, 12 insertions(+), 8 deletions(-) diff --git a/modules/clients/src/test/java/org/apache/ignite/jdbc/thin/JdbcThinConnectionSSLTest.java b/modules/clients/src/test/java/org/apache/ignite/jdbc/thin/JdbcThinConnectionSSLTest.java index 1bc993211b066..df6b49e4d2a02 100644 --- a/modules/clients/src/test/java/org/apache/ignite/jdbc/thin/JdbcThinConnectionSSLTest.java +++ b/modules/clients/src/test/java/org/apache/ignite/jdbc/thin/JdbcThinConnectionSSLTest.java @@ -336,8 +336,7 @@ public void testCustomCiphersOnServer() throws Exception { */ @Test public void testDisabledCustomCipher() throws Exception { - Set disabledSuites = disabledByDefaultCipherSuites(); - String disabledSuite = disabledSuites.iterator().next(); + String disabledSuite = disabledByDefaultCipherSuites().iterator().next(); System.out.println("Run test with cipher suite: " + disabledSuite); @@ -376,7 +375,7 @@ public void testDisabledCustomCipher() throws Exception { String completelyDisabledSuite = "TLS_RSA_WITH_DES_CBC_SHA"; - assertFalse(supportedCipherSuites().contains(completelyDisabledSuite)); + assertFalse(Set.of(factory("TLS").getSupportedCipherSuites()).contains(completelyDisabledSuite)); // Java 17+, the cipher suite TLS_RSA_WITH_NULL_SHA256 is completely disabled by default. GridTestUtils.assertThrows(log, () -> { @@ -767,16 +766,21 @@ private Set supportedCipherSuites() throws Exception { } /** */ - private Set disabledByDefaultCipherSuites() throws Exception { - SSLContext ctx = SSLContext.getInstance("TLSv1.2"); + private SSLSocketFactory factory(String protocol) throws Exception { + SSLContext ctx = SSLContext.getInstance(protocol); ctx.init(null, null, null); - SSLSocketFactory factory = ctx.getSocketFactory(); - Set dfltCiphersSuites = Set.of(factory.getDefaultCipherSuites()); + return ctx.getSocketFactory(); + } + + /** */ + private Set disabledByDefaultCipherSuites() throws Exception { + SSLSocketFactory factory = factory("TLSv1.2"); + Set supportedCiphersSuites = new HashSet<>(Arrays.stream(factory.getSupportedCipherSuites()).toList()); // Fulter supported, but NOT in the default active list. - supportedCiphersSuites.removeAll(dfltCiphersSuites); + supportedCiphersSuites.removeAll(Set.of(factory.getDefaultCipherSuites())); // Current TC settings. supportedCiphersSuites.removeIf(s -> s.contains("_anon_")); From 1c3c8e8f18244b1605bef31ce11096ea28a46277 Mon Sep 17 00:00:00 2001 From: zstan Date: Mon, 14 Sep 2026 16:51:20 +0300 Subject: [PATCH 10/10] rm supportedCipherSuites --- .../ignite/jdbc/thin/JdbcThinConnectionSSLTest.java | 11 ----------- 1 file changed, 11 deletions(-) diff --git a/modules/clients/src/test/java/org/apache/ignite/jdbc/thin/JdbcThinConnectionSSLTest.java b/modules/clients/src/test/java/org/apache/ignite/jdbc/thin/JdbcThinConnectionSSLTest.java index df6b49e4d2a02..c97fbe559117a 100644 --- a/modules/clients/src/test/java/org/apache/ignite/jdbc/thin/JdbcThinConnectionSSLTest.java +++ b/modules/clients/src/test/java/org/apache/ignite/jdbc/thin/JdbcThinConnectionSSLTest.java @@ -754,17 +754,6 @@ public static class TestSSLFactory implements Factory { } } - /** */ - private Set supportedCipherSuites() throws Exception { - // Initialize a standard SSL/TLS context to load all protocols - SSLContext ctx = SSLContext.getInstance("TLS"); - ctx.init(null, null, null); - SSLSocketFactory factory = ctx.getSocketFactory(); - - // Retrieve all available cipher suites - return Set.of(factory.getSupportedCipherSuites()); - } - /** */ private SSLSocketFactory factory(String protocol) throws Exception { SSLContext ctx = SSLContext.getInstance(protocol);