Skip to content

Commit 7c2ea96

Browse files
[TEST] Updated smoke test JDK's trusted certs (#72594)
The list of trusted CAs in the latest OpenJDK builds has changed: https://bugs.java.com/bugdatabase/view_bug.do?bug_id=JDK-8243559 This PR updates the default jdk trust config smoke test. Closes #71717
1 parent c853af5 commit 7c2ea96

File tree

1 file changed

+4
-5
lines changed

1 file changed

+4
-5
lines changed

libs/ssl-config/src/test/java/org/elasticsearch/common/ssl/DefaultJdkTrustConfigTests.java

Lines changed: 4 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -26,15 +26,13 @@ public class DefaultJdkTrustConfigTests extends ESTestCase {
2626

2727
private static final BiFunction<String, String, String> EMPTY_SYSTEM_PROPERTIES = (key, defaultValue) -> defaultValue;
2828

29-
@AwaitsFix(bugUrl = "https://github.com/elastic/elasticsearch/issues/71717")
3029
public void testGetSystemTrustStoreWithNoSystemProperties() throws Exception {
3130
final DefaultJdkTrustConfig trustConfig = new DefaultJdkTrustConfig((key, defaultValue) -> defaultValue);
3231
assertThat(trustConfig.getDependentFiles(), emptyIterable());
3332
final X509ExtendedTrustManager trustManager = trustConfig.createTrustManager();
3433
assertStandardIssuers(trustManager);
3534
}
3635

37-
@AwaitsFix(bugUrl = "https://github.com/elastic/elasticsearch/issues/71717")
3836
public void testGetNonPKCS11TrustStoreWithPasswordSet() throws Exception {
3937
final DefaultJdkTrustConfig trustConfig = new DefaultJdkTrustConfig(EMPTY_SYSTEM_PROPERTIES, "fakepassword".toCharArray());
4038
assertThat(trustConfig.getDependentFiles(), emptyIterable());
@@ -46,11 +44,12 @@ private void assertStandardIssuers(X509ExtendedTrustManager trustManager) {
4644
assertThat(trustManager.getAcceptedIssuers(), not(emptyArray()));
4745
// This is a sample of the CAs that we expect on every JRE.
4846
// We can safely change this list if the JRE's issuer list changes, but we want to assert something useful.
49-
assertHasTrustedIssuer(trustManager, "VeriSign");
50-
assertHasTrustedIssuer(trustManager, "GeoTrust");
5147
assertHasTrustedIssuer(trustManager, "DigiCert");
52-
assertHasTrustedIssuer(trustManager, "thawte");
5348
assertHasTrustedIssuer(trustManager, "COMODO");
49+
assertHasTrustedIssuer(trustManager, "GlobalSign");
50+
assertHasTrustedIssuer(trustManager, "GoDaddy");
51+
assertHasTrustedIssuer(trustManager, "QuoVadis");
52+
assertHasTrustedIssuer(trustManager, "Internet Security Research Group");
5453
}
5554

5655
private void assertHasTrustedIssuer(X509ExtendedTrustManager trustManager, String name) {

0 commit comments

Comments
 (0)