spring-cloud / spring-cloud/spring-cloud-config

Add ability to configure config client TLS enabled protocol versions and cipher suites via Spring properties

Open
#1,827 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

enhancement waiting for votes
Dominant language
Java
Stars
2k
Forks
1.3k
Avg merge
2d 59m
Merged PRs (30d)
16

Description

I'd like the ability to configure via Spring properties the enabled TLS protocol versions and cipher suites on the Spring Cloud Config HTTP client. The only way to do this currently is to provide a custom ConfigServicePropertySourceLocator bean with a RestTemplate that uses a ClientHttpRequestFactory that is basically a copy of the one created by org.springframework.cloud.config.client.ConfigServicePropertySourceLocator.createHttpRquestFactory(ConfigClientProperties) but with the enabled protocol versions and cipher suites set on an underlying org.apache.http.conn.ssl.SSLConnectionSocketFactory.

Thoughts?

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start in ConfigServicePropertySourceLocator, especially createHttpRquestFactory(ConfigClientProperties), and trace how the RestTemplate and ClientHttpRequestFactory are built. Review the underlying SSLConnectionSocketFactory configuration and determine how Spring properties should expose enabled TLS protocol versions and cipher suites. Done means the HTTP client can receive both settings through Spring properties without requiring a custom bean.

Written by the indexing model from the issue text.

Assessment

Tech stack
java, spring, spring-boot
Domain
api, backend
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.