Opened 12 years ago

Closed 9 years ago

#665 closed defect (fixed)

IZ3005: jgdi SSL connections from one client jvm to different SGE cluster might not work

Reported by: rhierlmeier Owned by:
Priority: high Milestone:
Component: sge Version: 6.2
Severity: minor Keywords: Sun jgdi


[Imported from gridengine issuezilla]

        Issue #:      3005             Platform:     Sun      Reporter: rhierlmeier (rhierlmeier)
       Component:     gridengine          OS:        All
     Subcomponent:    jgdi             Version:      6.2         CC:    None defined
        Status:       NEW              Priority:     P2
      Resolution:                     Issue type:    DEFECT
                                   Target milestone: ---
      Assigned to:    andre (andre)
      QA Contact:     andre
       * Summary:     jgdi SSL connections from one client jvm to different SGE cluster might not work
   Status whiteboard:

     Issue 3005 blocks:
   Votes for issue 3005:

   Opened: Sun Apr 19 22:34:00 -0700 2009 

If in one jvm opens serveral jgdi connections to different qmasters at nearly the same time the SSL certificate validate can fail, even if
valid keystores and certificates are used.

The user see the following error message:

Caused by PKIX path building failed: unable to find valid certification path to requested target

The problem is a bug in class The following member
variables must not be declared static:

public final class SSLHelper {
    private static SSLContext ctx;
    private static final GECAKeyManager keyManager = new GECAKeyManager();
    private static final GECATrustManager trustManager = new GECATrustManager();
    private static final Lock lock = new ReentrantLock();

However they are static and hence each jgdi connection gets the same SSLContext for a short time frame.

This is not a security vulnerability because the SSLContext is mixed up the SSL validation fails always.

Change History (1)

comment:1 Changed 9 years ago by dlove

  • Resolution set to fixed
  • Severity set to minor
  • Status changed from new to closed


Note: See TracTickets for help on using tickets.