Skip to content

Commit b77c11d

Browse files
transport-api: add ability to use a javax SSLContext with TLS (#3438)
#### Motivation The javax SSLContext is sometimes used as a way to pass through credentials and trust stores. #### Modifications Add a `.sslContext(SSLContext)` method to our SslConfig types and thread it through the netty API in to the JdkSslContext type which will then use the provided SSLContext as the engine for the SslHandler.
1 parent 705a750 commit b77c11d

File tree

8 files changed

+311
-22
lines changed

8 files changed

+311
-22
lines changed
Lines changed: 107 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,107 @@
1+
/*
2+
* Copyright © 2026 Apple Inc. and the ServiceTalk project authors
3+
*
4+
* Licensed under the Apache License, Version 2.0 (the "License");
5+
* you may not use this file except in compliance with the License.
6+
* You may obtain a copy of the License at
7+
*
8+
* http://www.apache.org/licenses/LICENSE-2.0
9+
*
10+
* Unless required by applicable law or agreed to in writing, software
11+
* distributed under the License is distributed on an "AS IS" BASIS,
12+
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13+
* See the License for the specific language governing permissions and
14+
* limitations under the License.
15+
*/
16+
package io.servicetalk.http.netty;
17+
18+
import io.servicetalk.http.api.BlockingHttpClient;
19+
import io.servicetalk.http.api.HttpResponseStatus;
20+
import io.servicetalk.test.resources.DefaultTestCerts;
21+
import io.servicetalk.transport.api.ClientSslConfigBuilder;
22+
import io.servicetalk.transport.api.ServerContext;
23+
import io.servicetalk.transport.api.ServerSslConfigBuilder;
24+
25+
import org.junit.jupiter.api.Test;
26+
27+
import java.io.InputStream;
28+
import java.security.KeyStore;
29+
import java.security.cert.Certificate;
30+
import java.security.cert.CertificateFactory;
31+
import javax.net.ssl.KeyManagerFactory;
32+
import javax.net.ssl.SSLContext;
33+
import javax.net.ssl.TrustManagerFactory;
34+
35+
import static io.servicetalk.test.resources.DefaultTestCerts.serverPemHostname;
36+
import static io.servicetalk.transport.api.SslClientAuthMode.REQUIRE;
37+
import static io.servicetalk.transport.netty.internal.AddressUtils.localAddress;
38+
import static io.servicetalk.transport.netty.internal.AddressUtils.serverHostAndPort;
39+
import static org.junit.jupiter.api.Assertions.assertEquals;
40+
41+
class SslContextTest {
42+
43+
private static final char[] KEYSTORE_PASSWORD = "changeit".toCharArray();
44+
45+
@Test
46+
void mutualSslWithSSLContext() throws Exception {
47+
SSLContext serverSslContext = createServerSSLContextWithClientAuth();
48+
try (ServerContext serverContext = HttpServers.forAddress(localAddress(0))
49+
.sslConfig(new ServerSslConfigBuilder(serverSslContext)
50+
.clientAuthMode(REQUIRE)
51+
.build())
52+
.listenBlockingAndAwait((ctx, request, responseFactory) -> responseFactory.ok())) {
53+
SSLContext clientSslContext = createClientSSLContextWithKeyMaterial();
54+
try (BlockingHttpClient client = HttpClients.forSingleAddress(serverHostAndPort(serverContext))
55+
.sslConfig(new ClientSslConfigBuilder(clientSslContext)
56+
.peerHost(serverPemHostname())
57+
.build())
58+
.buildBlocking()) {
59+
assertEquals(HttpResponseStatus.OK, client.request(client.get("/")).status());
60+
}
61+
}
62+
}
63+
64+
private static SSLContext createClientSSLContextWithKeyMaterial() throws Exception {
65+
KeyManagerFactory kmf = createKeyManagerFactory(DefaultTestCerts::loadClientP12);
66+
TrustManagerFactory tmf = createTrustManagerFactory(DefaultTestCerts::loadServerCAPem);
67+
return createSSLContext(kmf, tmf);
68+
}
69+
70+
private static SSLContext createServerSSLContextWithClientAuth() throws Exception {
71+
KeyManagerFactory kmf = createKeyManagerFactory(DefaultTestCerts::loadServerP12);
72+
TrustManagerFactory tmf = createTrustManagerFactory(DefaultTestCerts::loadClientCAPem);
73+
return createSSLContext(kmf, tmf);
74+
}
75+
76+
private static KeyManagerFactory createKeyManagerFactory(java.util.function.Supplier<InputStream> p12Supplier)
77+
throws Exception {
78+
KeyStore keyStore = KeyStore.getInstance("PKCS12");
79+
try (InputStream is = p12Supplier.get()) {
80+
keyStore.load(is, KEYSTORE_PASSWORD);
81+
}
82+
KeyManagerFactory kmf = KeyManagerFactory.getInstance(KeyManagerFactory.getDefaultAlgorithm());
83+
kmf.init(keyStore, KEYSTORE_PASSWORD);
84+
return kmf;
85+
}
86+
87+
private static TrustManagerFactory createTrustManagerFactory(java.util.function.Supplier<InputStream> caPemSupplier)
88+
throws Exception {
89+
CertificateFactory cf = CertificateFactory.getInstance("X.509");
90+
Certificate caCert;
91+
try (InputStream is = caPemSupplier.get()) {
92+
caCert = cf.generateCertificate(is);
93+
}
94+
KeyStore trustStore = KeyStore.getInstance(KeyStore.getDefaultType());
95+
trustStore.load(null, null);
96+
trustStore.setCertificateEntry("ca", caCert);
97+
TrustManagerFactory tmf = TrustManagerFactory.getInstance(TrustManagerFactory.getDefaultAlgorithm());
98+
tmf.init(trustStore);
99+
return tmf;
100+
}
101+
102+
private static SSLContext createSSLContext(KeyManagerFactory kmf, TrustManagerFactory tmf) throws Exception {
103+
SSLContext sslContext = SSLContext.getInstance("TLS");
104+
sslContext.init(kmf.getKeyManagers(), tmf.getTrustManagers(), null);
105+
return sslContext;
106+
}
107+
}

servicetalk-transport-api/src/main/java/io/servicetalk/transport/api/AbstractSslConfig.java

Lines changed: 12 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -21,9 +21,12 @@
2121
import java.util.function.Supplier;
2222
import javax.annotation.Nullable;
2323
import javax.net.ssl.KeyManagerFactory;
24+
import javax.net.ssl.SSLContext;
2425
import javax.net.ssl.TrustManagerFactory;
2526

2627
abstract class AbstractSslConfig implements SslConfig {
28+
@Nullable
29+
private final SSLContext sslContext;
2730
@Nullable
2831
private final TrustManagerFactory trustManagerFactory;
2932
@Nullable
@@ -52,7 +55,8 @@ abstract class AbstractSslConfig implements SslConfig {
5255
private final List<CertificateCompressionAlgorithm> certificateCompressionAlgorithms;
5356
private final Duration handshakeTimeout;
5457

55-
AbstractSslConfig(@Nullable final TrustManagerFactory trustManagerFactory,
58+
AbstractSslConfig(@Nullable final SSLContext sslContext,
59+
@Nullable final TrustManagerFactory trustManagerFactory,
5660
@Nullable final Supplier<InputStream> trustCertChainSupplier,
5761
@Nullable final KeyManagerFactory keyManagerFactory,
5862
@Nullable final Supplier<InputStream> keyCertChainSupplier,
@@ -64,6 +68,7 @@ abstract class AbstractSslConfig implements SslConfig {
6468
final int maxCertificateListBytes, @Nullable final SslProvider provider,
6569
@Nullable final List<CertificateCompressionAlgorithm> certificateCompressionAlgorithms,
6670
final Duration handshakeTimeout) {
71+
this.sslContext = sslContext;
6772
this.trustManagerFactory = trustManagerFactory;
6873
this.trustCertChainSupplier = trustCertChainSupplier;
6974
this.keyManagerFactory = keyManagerFactory;
@@ -82,6 +87,12 @@ abstract class AbstractSslConfig implements SslConfig {
8287
this.handshakeTimeout = handshakeTimeout;
8388
}
8489

90+
@Nullable
91+
@Override
92+
public final SSLContext sslContext() {
93+
return sslContext;
94+
}
95+
8596
@Nullable
8697
@Override
8798
public final TrustManagerFactory trustManagerFactory() {

servicetalk-transport-api/src/main/java/io/servicetalk/transport/api/AbstractSslConfigBuilder.java

Lines changed: 44 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -24,6 +24,7 @@
2424
import java.util.function.Supplier;
2525
import javax.annotation.Nullable;
2626
import javax.net.ssl.KeyManagerFactory;
27+
import javax.net.ssl.SSLContext;
2728
import javax.net.ssl.SSLEngine;
2829
import javax.net.ssl.SSLSessionContext;
2930
import javax.net.ssl.TrustManagerFactory;
@@ -44,6 +45,8 @@ abstract class AbstractSslConfigBuilder<T extends AbstractSslConfigBuilder<T>> {
4445
static final Duration DEFAULT_HANDSHAKE_TIMEOUT = ofSeconds(5);
4546
private static final int DEFAULT_MAX_CERTIFICATE_LIST_BYTES = 32 * 1024; // 32Kb
4647

48+
@Nullable
49+
private SSLContext sslContext;
4750
@Nullable
4851
private TrustManagerFactory trustManagerFactory;
4952
@Nullable
@@ -72,6 +75,42 @@ abstract class AbstractSslConfigBuilder<T extends AbstractSslConfigBuilder<T>> {
7275
private List<CertificateCompressionAlgorithm> certificateCompressionAlgorithms;
7376
private Duration handshakeTimeout = DEFAULT_HANDSHAKE_TIMEOUT;
7477

78+
/**
79+
* Set a pre-configured {@link SSLContext} to use for SSL/TLS.
80+
* <p>
81+
* When an {@link SSLContext} is provided, it takes precedence over individual trust and key manager
82+
* configurations and forces the {@link SslProvider} to JDK.
83+
* <p>
84+
* This method is mutually exclusive with:
85+
* <ul>
86+
* <li>{@link #trustManager(TrustManagerFactory)}</li>
87+
* <li>{@link #trustManager(Supplier)}</li>
88+
* <li>{@link #keyManager(KeyManagerFactory)}</li>
89+
* <li>{@link #keyManager(Supplier, Supplier)}</li>
90+
* <li>{@link #keyManager(Supplier, Supplier, String)}</li>
91+
* </ul>
92+
*
93+
* @param sslContext the SSLContext to use
94+
* @return {@code this}
95+
* @see SslConfig#sslContext()
96+
*/
97+
public final T sslContext(final SSLContext sslContext) {
98+
this.sslContext = requireNonNull(sslContext);
99+
// Clear individual manager configurations as they conflict with SSLContext
100+
trustManagerFactory = null;
101+
trustCertChainSupplier = null;
102+
keyManagerFactory = null;
103+
keyCertChainSupplier = null;
104+
keySupplier = null;
105+
keyPassword = null;
106+
return thisT();
107+
}
108+
109+
@Nullable
110+
final SSLContext sslContext() {
111+
return sslContext;
112+
}
113+
75114
/**
76115
* Set the {@link TrustManagerFactory} used for verifying the remote endpoint's certificate.
77116
*
@@ -82,6 +121,7 @@ abstract class AbstractSslConfigBuilder<T extends AbstractSslConfigBuilder<T>> {
82121
public final T trustManager(TrustManagerFactory tmf) {
83122
this.trustManagerFactory = requireNonNull(tmf);
84123
trustCertChainSupplier = null;
124+
sslContext = null;
85125
return thisT();
86126
}
87127

@@ -105,6 +145,7 @@ final TrustManagerFactory trustManager() {
105145
public final T trustManager(Supplier<InputStream> trustCertChainSupplier) {
106146
this.trustCertChainSupplier = requireNonNull(trustCertChainSupplier);
107147
trustManagerFactory = null;
148+
sslContext = null;
108149
return thisT();
109150
}
110151

@@ -125,6 +166,7 @@ public final T keyManager(KeyManagerFactory kmf) {
125166
keyCertChainSupplier = null;
126167
keySupplier = null;
127168
keyPassword = null;
169+
sslContext = null;
128170
return thisT();
129171
}
130172

@@ -155,6 +197,7 @@ public final T keyManager(Supplier<InputStream> keyCertChainSupplier, Supplier<I
155197
this.keySupplier = requireNonNull(keySupplier);
156198
keyPassword = null;
157199
keyManagerFactory = null;
200+
sslContext = null;
158201
return thisT();
159202
}
160203

@@ -183,6 +226,7 @@ public final T keyManager(Supplier<InputStream> keyCertChainSupplier, Supplier<I
183226
this.keySupplier = requireNonNull(keySupplier);
184227
this.keyPassword = keyPassword;
185228
keyManagerFactory = null;
229+
sslContext = null;
186230
return thisT();
187231
}
188232

servicetalk-transport-api/src/main/java/io/servicetalk/transport/api/ClientSslConfigBuilder.java

Lines changed: 16 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -21,6 +21,7 @@
2121
import java.util.function.Supplier;
2222
import javax.annotation.Nullable;
2323
import javax.net.ssl.KeyManagerFactory;
24+
import javax.net.ssl.SSLContext;
2425
import javax.net.ssl.SSLEngine;
2526
import javax.net.ssl.SSLParameters;
2627
import javax.net.ssl.TrustManagerFactory;
@@ -50,6 +51,16 @@ public final class ClientSslConfigBuilder extends AbstractSslConfigBuilder<Clien
5051
public ClientSslConfigBuilder() {
5152
}
5253

54+
/**
55+
* Create a new instance using a {@link SSLContext} for key and trust configuration.
56+
*
57+
* @param sslContext the {@link SSLContext} to use for SSL/TLS.
58+
* @see ClientSslConfig#sslContext()
59+
*/
60+
public ClientSslConfigBuilder(SSLContext sslContext) {
61+
sslContext(sslContext);
62+
}
63+
5364
/**
5465
* Create a new instance using {@code tmf} to verify trusted servers.
5566
*
@@ -142,7 +153,7 @@ public ClientSslConfigBuilder sniHostname(String sniHostname) {
142153
* @return a new {@link ClientSslConfig}.
143154
*/
144155
public ClientSslConfig build() {
145-
return new DefaultClientSslConfig(hostnameVerificationAlgorithm, peerHost, peerPort, sniHostname,
156+
return new DefaultClientSslConfig(sslContext(), hostnameVerificationAlgorithm, peerHost, peerPort, sniHostname,
146157
trustManager(), trustCertChainSupplier(), keyManager(), keyCertChainSupplier(), keySupplier(),
147158
keyPassword(), sslProtocols(), alpnProtocols(), ciphers(), cipherSuiteFilter(), sessionCacheSize(),
148159
sessionTimeout(), maxCertificateListBytes(), provider(), certificateCompressionAlgorithms(),
@@ -163,7 +174,8 @@ private static final class DefaultClientSslConfig extends AbstractSslConfig impl
163174
@Nullable
164175
private final String sniHostname;
165176

166-
DefaultClientSslConfig(@Nullable final String hostnameVerificationAlgorithm,
177+
DefaultClientSslConfig(@Nullable final SSLContext sslContext,
178+
@Nullable final String hostnameVerificationAlgorithm,
167179
@Nullable final String peerHost,
168180
final int peerPort,
169181
@Nullable final String sniHostname,
@@ -178,8 +190,8 @@ private static final class DefaultClientSslConfig extends AbstractSslConfig impl
178190
final int maxCertificateListBytes, @Nullable final SslProvider provider,
179191
@Nullable final List<CertificateCompressionAlgorithm> certificateCompressionAlgorithms,
180192
final Duration handshakeTimeout) {
181-
super(trustManagerFactory, trustCertChainSupplier, keyManagerFactory, keyCertChainSupplier, keySupplier,
182-
keyPassword, sslProtocols, alpnProtocols, ciphers, cipherSuiteFilter, sessionCacheSize,
193+
super(sslContext, trustManagerFactory, trustCertChainSupplier, keyManagerFactory, keyCertChainSupplier,
194+
keySupplier, keyPassword, sslProtocols, alpnProtocols, ciphers, cipherSuiteFilter, sessionCacheSize,
183195
sessionTimeout, maxCertificateListBytes, provider, certificateCompressionAlgorithms,
184196
handshakeTimeout);
185197
this.hostnameVerificationAlgorithm = hostnameVerificationAlgorithm;

servicetalk-transport-api/src/main/java/io/servicetalk/transport/api/DelegatingSslConfig.java

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -21,6 +21,7 @@
2121
import java.util.function.Supplier;
2222
import javax.annotation.Nullable;
2323
import javax.net.ssl.KeyManagerFactory;
24+
import javax.net.ssl.SSLContext;
2425
import javax.net.ssl.TrustManagerFactory;
2526

2627
import static java.util.Objects.requireNonNull;
@@ -138,4 +139,10 @@ public Duration handshakeTimeout() {
138139
public int maxCertificateListBytes() {
139140
return delegate.maxCertificateListBytes();
140141
}
142+
143+
@Nullable
144+
@Override
145+
public SSLContext sslContext() {
146+
return delegate.sslContext();
147+
}
141148
}

servicetalk-transport-api/src/main/java/io/servicetalk/transport/api/ServerSslConfigBuilder.java

Lines changed: 19 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -21,6 +21,7 @@
2121
import java.util.function.Supplier;
2222
import javax.annotation.Nullable;
2323
import javax.net.ssl.KeyManagerFactory;
24+
import javax.net.ssl.SSLContext;
2425
import javax.net.ssl.SSLParameters;
2526
import javax.net.ssl.TrustManagerFactory;
2627

@@ -33,6 +34,16 @@
3334
public final class ServerSslConfigBuilder extends AbstractSslConfigBuilder<ServerSslConfigBuilder> {
3435
private SslClientAuthMode clientAuthMode = NONE;
3536

37+
/**
38+
* Create a new instance using a {@link SSLContext} for key and trust configuration.
39+
*
40+
* @param sslContext the {@link SSLContext} to use for SSL/TLS.
41+
* @see ServerSslConfig#sslContext()
42+
*/
43+
public ServerSslConfigBuilder(SSLContext sslContext) {
44+
sslContext(sslContext);
45+
}
46+
3647
/**
3748
* Create a new instance using the {@link KeyManagerFactory} for SSL/TLS handshakes.
3849
*
@@ -106,10 +117,10 @@ public ServerSslConfigBuilder clientAuthMode(SslClientAuthMode clientAuthMode) {
106117
* @return a new {@link ServerSslConfig}.
107118
*/
108119
public ServerSslConfig build() {
109-
return new DefaultServerSslConfig(clientAuthMode, trustManager(), trustCertChainSupplier(), keyManager(),
110-
keyCertChainSupplier(), keySupplier(), keyPassword(), sslProtocols(), alpnProtocols(), ciphers(),
111-
cipherSuiteFilter(), sessionCacheSize(), sessionTimeout(), maxCertificateListBytes(), provider(),
112-
certificateCompressionAlgorithms(), handshakeTimeout());
120+
return new DefaultServerSslConfig(sslContext(), clientAuthMode, trustManager(), trustCertChainSupplier(),
121+
keyManager(), keyCertChainSupplier(), keySupplier(), keyPassword(), sslProtocols(), alpnProtocols(),
122+
ciphers(), cipherSuiteFilter(), sessionCacheSize(), sessionTimeout(), maxCertificateListBytes(),
123+
provider(), certificateCompressionAlgorithms(), handshakeTimeout());
113124
}
114125

115126
@Override
@@ -120,7 +131,8 @@ protected ServerSslConfigBuilder thisT() {
120131
private static final class DefaultServerSslConfig extends AbstractSslConfig implements ServerSslConfig {
121132
private final SslClientAuthMode clientAuthMode;
122133

123-
DefaultServerSslConfig(SslClientAuthMode clientAuthMode,
134+
DefaultServerSslConfig(@Nullable final SSLContext sslContext,
135+
SslClientAuthMode clientAuthMode,
124136
@Nullable final TrustManagerFactory trustManagerFactory,
125137
@Nullable final Supplier<InputStream> trustCertChainSupplier,
126138
@Nullable final KeyManagerFactory keyManagerFactory,
@@ -132,8 +144,8 @@ private static final class DefaultServerSslConfig extends AbstractSslConfig impl
132144
final int maxCertificateListBytes, @Nullable final SslProvider provider,
133145
@Nullable final List<CertificateCompressionAlgorithm> certificateCompressionAlgorithms,
134146
final Duration handshakeTimeout) {
135-
super(trustManagerFactory, trustCertChainSupplier, keyManagerFactory, keyCertChainSupplier, keySupplier,
136-
keyPassword, sslProtocols, alpnProtocols, ciphers, cipherSuiteFilter, sessionCacheSize,
147+
super(sslContext, trustManagerFactory, trustCertChainSupplier, keyManagerFactory, keyCertChainSupplier,
148+
keySupplier, keyPassword, sslProtocols, alpnProtocols, ciphers, cipherSuiteFilter, sessionCacheSize,
137149
sessionTimeout, maxCertificateListBytes, provider, certificateCompressionAlgorithms,
138150
handshakeTimeout);
139151
this.clientAuthMode = clientAuthMode;

0 commit comments

Comments
 (0)