Skip to content

External Chaincode Mutual TLS #625

Description

@aminchegeni

Description

When using the Java shim as an external chaincode server, setting client_auth_required to true in the packaged connection.json does not appear to enable mutual TLS with the default server configuration.

NettyGrpcServer.configureTls() only requires and validates client certificates when ChaincodeServerProperties.trustCertCollectionFile is set. However, ChaincodeBase.getChaincodeServerConfig() enables TLS and sets the server certificate and key, but does not set that trust-certificate property.

In my test, the peer connected and chaincode communication succeeded even though connection.json contained invalid client_key and client_cert values. I expected the connection to fail if client authentication was required. This is an observation from my Java chaincode setup.

Steps to reproduce

  1. Start a Java external chaincode server with TLS enabled, configuring its server certificate and key but not a trust certificate collection for peer client certificates.

  2. Set client_auth_required to true in the external chaincode package’s connection.json.

  3. Set client_key and client_cert to invalid test values, for example:

    {
      "client_auth_required": "true",
      "client_key": "invalid test key",
      "client_cert": "invalid test certificate"
    }

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions