spring-cloud / spring-cloud/spring-cloud-config
Add ability to configure config client TLS enabled protocol versions and cipher suites via Spring properties
Nobody has claimed this yet.
- Dominant language
- Java
- Stars
- 2k
- Forks
- 1.3k
- Avg merge
- 2d 59m
- Merged PRs (30d)
- 16
Description
I'd like the ability to configure via Spring properties the enabled TLS protocol versions and cipher suites on the Spring Cloud Config HTTP client. The only way to do this currently is to provide a custom ConfigServicePropertySourceLocator bean with a RestTemplate that uses a ClientHttpRequestFactory that is basically a copy of the one created by org.springframework.cloud.config.client.ConfigServicePropertySourceLocator.createHttpRquestFactory(ConfigClientProperties) but with the enabled protocol versions and cipher suites set on an underlying org.apache.http.conn.ssl.SSLConnectionSocketFactory.
Thoughts?
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start in ConfigServicePropertySourceLocator, especially createHttpRquestFactory(ConfigClientProperties), and trace how the RestTemplate and ClientHttpRequestFactory are built. Review the underlying SSLConnectionSocketFactory configuration and determine how Spring properties should expose enabled TLS protocol versions and cipher suites. Done means the HTTP client can receive both settings through Spring properties without requiring a custom bean.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java, spring, spring-boot
- Domain
- api, backend
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100