Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Allow empty keyStore file for keyStoreTypes that do not require files #47

Closed
wants to merge 2 commits into from

Conversation

kolbe
Copy link

@kolbe kolbe commented Feb 13, 2020

This PR adds simple handling for an empty keyStore file, for use with KeyStoreManagers that do not require a defined keystore.

One such example is SPIFFE with java-spiffe: https://github.com/spiffe/java-spiffe.

@kolbe
Copy link
Author

kolbe commented Feb 13, 2020

As long as the KeyManager implements a no-op KeyStoreSpi.engineLoad() (As java-spiffe does), a workaround for this issue is to create a "dummy" certificate (openssl req -x509 -new -out dummy.pem), load it into a "dummy" keystore (keytool -importcert -keystore dummy.keystore -storepass nopass -keypass nopass -file dummy.pem -noprompt), and use &clientCertificateKeyStoreUrl=file:dummy.keystore&clientCertificateKeyStorePassword=nopass in your JDBC connection URI.

Connector/J will try to load the keystore into the KeyManager, but the KeyManager simply ignores the attempt and will use key material it has acquired elsewhere.

@mysql-oca-bot
Copy link

Hi, thank you for submitting this pull request. In order to consider your code we need you to sign the Oracle Contribution Agreement (OCA). Please review the details and follow the instructions at http://www.oracle.com/technetwork/community/oca-486395.html
Please make sure to include your MySQL bug system user (email) in the returned form.
Thanks

@mysql-oca-bot
Copy link

Hi, thank you for your contribution. Please confirm this code is submitted under the terms of the OCA (Oracle's Contribution Agreement) you have previously signed by cutting and pasting the following text as a comment:
"I confirm the code being submitted is offered under the terms of the OCA, and that I am authorized to contribute it."
Thanks

@kolbe
Copy link
Author

kolbe commented Feb 20, 2020

I confirm the code being submitted is offered under the terms of the OCA, and that I am authorized to contribute it.

@mysql-oca-bot
Copy link

Hi, thank you for your contribution. Your code has been assigned to an internal queue. Please follow
bug http://bugs.mysql.com/bug.php?id=98699 for updates.
Thanks

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
2 participants