Bug 1689163

Summary: (6.4.z) Ldaps tests failing on JDK 8u181
Product: [JBoss] JBoss Enterprise Application Platform 6 Reporter: Tomas Hofman <thofman>
Component: TestsuiteAssignee: jboss-set
Status: CLOSED CURRENTRELEASE QA Contact: Peter Mackay <pmackay>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: 6.4.21CC: bmaxwell, cdewolf, pmackay
Target Milestone: CR1   
Target Release: EAP 6.4.22   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2019-08-19 12:45:31 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 1613417    

Description Tomas Hofman 2019-03-15 10:33:23 UTC
LdapExtLoginModuleTestCase and LdapLoginModuleTestCase are failing with SSLHandshakeException


java.lang.AssertionError: Unexpected status code returned after the authentication. expected:<200> but was:<401>
	at org.junit.Assert.fail(Assert.java:88)
	at org.junit.Assert.failNotEquals(Assert.java:743)
	at org.junit.Assert.assertEquals(Assert.java:118)
	at org.junit.Assert.assertEquals(Assert.java:555)
	at org.jboss.as.test.integration.security.common.Utils.makeCallWithBasicAuthn(Utils.java:524)
	at org.jboss.as.test.integration.security.loginmodules.LdapExtLoginModuleTestCase.testDeployment(LdapExtLoginModuleTestCase.java:274)
	at org.jboss.as.test.integration.security.loginmodules.LdapExtLoginModuleTestCase.test2(LdapExtLoginModuleTestCase.java:197)



For LDAPS connections host verification check was added by default. See https://www.oracle.com/technetwork/java/javase/8u181-relnotes-4479407.html#JDK-8200666

Comment 2 Tomas Hofman 2019-03-15 11:11:09 UTC
@Brad, @Peter need acks. This is just a testsuite fix for JDK 8.

Comment 3 Tomas Hofman 2019-03-18 10:40:29 UTC
Exception in the test output:

05:04:28,525 WARN  [org.apache.directory.server.ldap.LdapProtocolHandler] (NioProcessor-10) Unexpected exception forcing session to close: sending disconnect notice to client.: javax.net.ssl.SSLHandshakeException: SSL handshake failed.
	at org.apache.mina.filter.ssl.SslFilter.messageReceived(SslFilter.java:487)
	at org.apache.mina.core.filterchain.DefaultIoFilterChain.callNextMessageReceived(DefaultIoFilterChain.java:417)
	at org.apache.mina.core.filterchain.DefaultIoFilterChain.access$1200(DefaultIoFilterChain.java:47)
	at org.apache.mina.core.filterchain.DefaultIoFilterChain$EntryImpl$1.messageReceived(DefaultIoFilterChain.java:765)
	at org.apache.mina.core.filterchain.IoFilterAdapter.messageReceived(IoFilterAdapter.java:109)
	at org.apache.mina.core.filterchain.DefaultIoFilterChain.callNextMessageReceived(DefaultIoFilterChain.java:417)
	at org.apache.mina.core.filterchain.DefaultIoFilterChain.fireMessageReceived(DefaultIoFilterChain.java:410)
	at org.apache.mina.core.polling.AbstractPollingIoProcessor.read(AbstractPollingIoProcessor.java:710)
	at org.apache.mina.core.polling.AbstractPollingIoProcessor.process(AbstractPollingIoProcessor.java:664)
	at org.apache.mina.core.polling.AbstractPollingIoProcessor.process(AbstractPollingIoProcessor.java:653)
	at org.apache.mina.core.polling.AbstractPollingIoProcessor.access$600(AbstractPollingIoProcessor.java:67)
	at org.apache.mina.core.polling.AbstractPollingIoProcessor$Processor.run(AbstractPollingIoProcessor.java:1124)
	at org.apache.mina.util.NamePreservingRunnable.run(NamePreservingRunnable.java:64)
	at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1149)
	at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:624)
	at java.lang.Thread.run(Thread.java:748)
Caused by: javax.net.ssl.SSLException: Received fatal alert: certificate_unknown
	at sun.security.ssl.Alerts.getSSLException(Alerts.java:208)
	at sun.security.ssl.SSLEngineImpl.fatal(SSLEngineImpl.java:1666)
	at sun.security.ssl.SSLEngineImpl.fatal(SSLEngineImpl.java:1634)
	at sun.security.ssl.SSLEngineImpl.recvAlert(SSLEngineImpl.java:1800)
	at sun.security.ssl.SSLEngineImpl.readRecord(SSLEngineImpl.java:1083)
	at sun.security.ssl.SSLEngineImpl.readNetRecord(SSLEngineImpl.java:907)
	at sun.security.ssl.SSLEngineImpl.unwrap(SSLEngineImpl.java:781)
	at javax.net.ssl.SSLEngine.unwrap(SSLEngine.java:624)
	at org.apache.mina.filter.ssl.SslHandler.unwrap(SslHandler.java:728)
	at org.apache.mina.filter.ssl.SslHandler.unwrapHandshake(SslHandler.java:666)
	at org.apache.mina.filter.ssl.SslHandler.handshake(SslHandler.java:552)
	at org.apache.mina.filter.ssl.SslHandler.messageReceived(SslHandler.java:351)
	at org.apache.mina.filter.ssl.SslFilter.messageReceived(SslFilter.java:468)
	... 15 more

Comment 6 Peter Mackay 2019-05-08 20:24:34 UTC
Regression tests passed
Verified with EAP 6.4.22.CP.CR1