spring-projects / spring-projects/spring-boot

Support for gRPC client TLS certificate rotation

Open
#49,831 8 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

theme: grpc type: enhancement
Dominant language
Java
Stars
81.5k
Forks
42.7k
Avg merge
2d 4h
Merged PRs (30d)
65

Description

There is a comment on grpc-java where it claims that this feature is already implemented. But is this available on Spring GRPC client ?

Been trying out something like this but it still keeps using the old certificate, even the keymanager picks up the new certficate

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reading the grpc-java issue comment and the linked CfClientCertificateConfig.java example, then investigate how Spring gRPC clients obtain and refresh their key material. Verify whether the client continues using the old certificate after rotation; done means the supported client configuration uses the new certificate without requiring a restart.

Written by the indexing model from the issue text.

Assessment

Tech stack
grpc, java, spring-boot
Domain
api, backend, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
42/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.