RFR: 8376031: HttpsURLConnection.getServerCertificates() throws "java.lang.IllegalStateException: connection not yet open" for the HEAD method

Daniel Fuchs dfuchs at openjdk.org
Fri Jan 30 15:34:03 UTC 2026


On Thu, 29 Jan 2026 15:32:50 GMT, Daniel Fuchs <dfuchs at openjdk.org> wrote:

> The issue here is that `HttpURLConnection` is automatically disconnected (`HttpClient` is set to `null`, `connected` is set to `false`) when a response with no response body bytes is received. This happens before a fake empty body input stream is returned to the user. That behaviour also occurs with any method for which `content-length: 0` is returned (GET, POST, custom, anything), and with any status code (204, 304) for which there is no body.
> 
> In this case, the proposed fix is to store the `SSLSession` in the `AbstractDelegateHttpsURLConnection` subclass until such a time where `disconnect()` is explicitely closed. Information pertaining to SSL, such as server certificates, can be extracted from the saved `SSLSession`.

Thank you Brett! Much appreciated.

-------------

PR Comment: https://git.openjdk.org/jdk/pull/29489#issuecomment-3824329058


More information about the security-dev mailing list