RFR: 8065422: Trailing dot in hostname causes TLS handshake to fail with SNI disabled [v3]
Weijun Wang
weijun at openjdk.java.net
Thu Feb 3 03:46:44 UTC 2022
On Thu, 3 Feb 2022 03:42:33 GMT, Xue-Lei Andrew Fan <xuelei at openjdk.org> wrote:
>> A hostname in an URL ending with a dot is valid (See RFC 1034). However, it is not a valid SNI hostname. The ending dot should be ignored while checking the hostname with SNI or the name in a X.509 certificate.
>>
>> The update could be verified with jshell.
>> $ $JDK_HOME/bin/jshell
>> jshell> URL url = new URL("https://www.google.com./");
>> jshell> URLConnection conn = url.openConnection();
>> jshell> conn.connect();
>
> Xue-Lei Andrew Fan has updated the pull request incrementally with one additional commit since the last revision:
>
> Update test copyright sections
Marked as reviewed by weijun (Reviewer).
-------------
PR: https://git.openjdk.java.net/jdk/pull/7205
More information about the security-dev
mailing list