Description
When using the Java shim as an external chaincode server, setting client_auth_required to true in the packaged connection.json does not appear to enable mutual TLS with the default server configuration.
NettyGrpcServer.configureTls() only requires and validates client certificates when ChaincodeServerProperties.trustCertCollectionFile is set. However, ChaincodeBase.getChaincodeServerConfig() enables TLS and sets the server certificate and key, but does not set that trust-certificate property.
In my test, the peer connected and chaincode communication succeeded even though connection.json contained invalid client_key and client_cert values. I expected the connection to fail if client authentication was required. This is an observation from my Java chaincode setup.
Steps to reproduce
-
Start a Java external chaincode server with TLS enabled, configuring its server certificate and key but not a trust certificate collection for peer client certificates.
-
Set client_auth_required to true in the external chaincode package’s connection.json.
-
Set client_key and client_cert to invalid test values, for example:
{
"client_auth_required": "true",
"client_key": "invalid test key",
"client_cert": "invalid test certificate"
}
Description
When using the Java shim as an external chaincode server, setting
client_auth_requiredtotruein the packagedconnection.jsondoes not appear to enable mutual TLS with the default server configuration.NettyGrpcServer.configureTls()only requires and validates client certificates whenChaincodeServerProperties.trustCertCollectionFileis set. However,ChaincodeBase.getChaincodeServerConfig()enables TLS and sets the server certificate and key, but does not set that trust-certificate property.In my test, the peer connected and chaincode communication succeeded even though
connection.jsoncontained invalidclient_keyandclient_certvalues. I expected the connection to fail if client authentication was required. This is an observation from my Java chaincode setup.Steps to reproduce
Start a Java external chaincode server with TLS enabled, configuring its server certificate and key but not a trust certificate collection for peer client certificates.
Set
client_auth_requiredtotruein the external chaincode package’sconnection.json.Set
client_keyandclient_certto invalid test values, for example:{ "client_auth_required": "true", "client_key": "invalid test key", "client_cert": "invalid test certificate" }