Skip to content

Conversation

stoty
Copy link
Contributor

@stoty stoty commented Jun 20, 2025

This includes fixes and docs updates for ZOOKEEPER-4090 ZOOKEEPER-4091 and ZOOKEEPER-4092

stoty added 2 commits June 19, 2025 07:06
- Enable server hostname verification if truststore is not specified
- Make sure tcnative specific enableOCSP method is not called for JRE SSL provider
- Add new config option to enable tcnative specific enableOCSP methid
- Add new config option to separetely enable certificate revocation checking
- Add new config option to disable existing implicit certificate revocation checking login
@stoty stoty marked this pull request as draft June 20, 2025 08:26
@stoty
Copy link
Contributor Author

stoty commented Jun 20, 2025

@anmolnar
This is a draft for the discussed TLS/CRL/OCSP changes as a single patch.

This takes a slightly different approach as the previous patches based on our discussions.

One new element is using your fallback hostname verification code if there is no custom truststore defined.

@stoty
Copy link
Contributor Author

stoty commented Jul 7, 2025

#2277 is the current patch

@stoty stoty closed this Jul 7, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant