Uploaded image for project: 'Apache NiFi'
  1. Apache NiFi
  2. NIFI-7468

Improve internal handling of SSL channels

    XMLWordPrintableJSON

Details

    Description

      While refactoring the TLS protocol version issue in NIFI-7407, I discovered that some processors make use of NiFi custom implementations of SSLSocketChannel, SSLCommsSession, and SSLSocketChannelInputStream. These implementations break on TLSv1.3.

      Further investigation is needed to determine why these custom implementations were provided originally, whether they are still required, and why they do not handle TLSv1.3 successfully.

      Diagnostic error:

      Error reading from channel due to Tag mismatch!: javax.net.ssl.SSLException: Tag mismatch!
      

      Attachments

        Issue Links

          Activity

            People

              exceptionfactory David Handermann
              alopresto Andy LoPresto
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Time Tracking

                  Estimated:
                  Original Estimate - Not Specified
                  Not Specified
                  Remaining:
                  Remaining Estimate - 0h
                  0h
                  Logged:
                  Time Spent - 2h 20m
                  2h 20m