Repository navigation
Conversation
With an explicit TLS version (e.g. SSLContext.new(:TLSv1_2)), and
always in the FIPS variant, SSLContext uses BCJSSE. BCJSSE asks the key
manager for "ECDHE_ECDSA" / "ECDHE_RSA" / "DHE_DSS" (TLS 1.2),
"EC/<group>" (TLS 1.3) or "Ed25519" / "Ed448", but chooseAlias compared
against the plain key type ("EC", "RSA", "EdDSA"). EC and Ed25519
server keys then got no credential and every handshake failed with
"found no selectable cipher suite".
Map these key types to the credential's key type, and for "EC/<group>"
also check that the key is on that curve.
Fixes jruby#383
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
BCJSSE in FIPS mode does not offer the ed25519 signature scheme, so an Ed25519 server key cannot be selected there regardless of key-type matching. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #383.
With an explicit TLS version (
SSLContext.new(:TLSv1_2)/ssl_version=), and always in the FIPS variant,SSLContextuses BCJSSE, which asks the key manager forECDHE_ECDSA/ECDHE_RSA/DHE_DSS(TLS 1.2),EC/<group>(TLS 1.3) orEd25519/Ed448.chooseAliascompared those against the plain key type, so EC and Ed25519 server keys never got a credential. This maps the requested key types to the credential's key type and, forEC/<group>, checks the key's curve.Adds
test_server_key_types_with_explicit_tls_version(P-256, P-384, Ed25519 on TLS 1.2 and 1.3): it fails on master and passes with the change;test/ssl/test_ssl.rbpasses otherwise unchanged (JRuby 9.4.15.0, OpenJDK 21).🤖 Generated with Claude Code