grpc / grpc/grpc-java

xds: Support UpstreamTlsContext.sni with XdsChannelCredentials

Open
#11,784 5 comments 0 reactions 1 assignee Claimed by @ejona86 View on GitHub
enhancement xds
Dominant language
Java
Stars
12.1k
Forks
4k
Avg merge
2d 17h
Merged PRs (30d)
37

Description

gRFC A29 added XdsChannelCredentials, but the gRFC explicitly ignored the `sni` field. @dvilaverde in #11750 needs `sni`, so this issue was split out to track it. We'll need a small gRFC.

The current implementation is sending `sni` based on the original target instead of not sending any SNI. That's not good as it could cause a user to unknowingly depend on the incorrect behavior. So we do need to _at least disable_ SNI in the short-term. But it seems the work to disable SNI is most of the work to support `sni`. (Even when we support `sni` we need to support disabling SNI; if the field is empty that implies SNI is disabled.)

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.