|
| 1 | +include::../shared-doc/attributes.adoc[] |
| 2 | + |
| 3 | += dynamic-client-ssl-context: Dynamic client SSL Context between Server and Client |
| 4 | +:author: Richard Záň |
| 5 | +:level: Intermidiate |
| 6 | +:technologies: Dynamic TLS, Security, Undertow |
| 7 | + |
| 8 | +[abstract] |
| 9 | +The dynamic-client-ssl-context quickstart shows the option to select different SSL/TLS configurations dynamically based on the host and port of the outbound connection. |
| 10 | + |
| 11 | +:standalone-server-type: default |
| 12 | +:archiveType: war |
| 13 | + |
| 14 | +== What is it? |
| 15 | + |
| 16 | +Elytron client supports dynamic client SSL context. It can be configured everywhere in the subsystem where client-ssl-context attribute can be configured. |
| 17 | + |
| 18 | +The `dynamic-client-ssl-context` quickstart demonstrates enabled dynamic SSL context for specified URLs and their ports. The only function they represent is to be called via provided REST client and pass as successful call through the SSL/TLS configuration. |
| 19 | + |
| 20 | +This example consists of the following two URLs, each with enabled dynamic SSL context: |
| 21 | + |
| 22 | +[cols="100%",options="headers"] |
| 23 | +|=== |
| 24 | +|URL paths with their ports |
| 25 | + |
| 26 | +|`https://localhost:9443/dynamic-client-ssl-context/` |
| 27 | + |
| 28 | +|`https://localhost:10443/dynamic-client-ssl-context/` |
| 29 | + |
| 30 | +|=== |
| 31 | + |
| 32 | +The server configuration is done using CLI batch scripts located in the root of the quickstart folder. |
| 33 | + |
| 34 | +// Link to the quickstart source |
| 35 | +include::../shared-doc/view-the-source.adoc[leveloffset=+1] |
| 36 | +// System Requirements |
| 37 | +include::../shared-doc/system-requirements.adoc[leveloffset=+1] |
| 38 | +// Use of {jbossHomeName} |
| 39 | +include::../shared-doc/use-of-jboss-home-name.adoc[leveloffset=+1] |
| 40 | + |
| 41 | +[[start_with_a_clean_server_install]] |
| 42 | +== Start with a Clean Server Install |
| 43 | + |
| 44 | +It is important to start with a clean version of {productName} before testing this quickstart. Make sure you unzip or install a fresh {productName} instance. |
| 45 | + |
| 46 | +// Back Up the {productName} Managed Domain Configuration |
| 47 | +include::../shared-doc/back-up-server-standalone-configuration.adoc[leveloffset=+1] |
| 48 | +// Start the {productName} Managed Domain |
| 49 | +include::../shared-doc/start-the-standalone-server.adoc[leveloffset=+1] |
| 50 | + |
| 51 | +// Build and Deploy the Quickstart |
| 52 | +include::../shared-doc/build-and-deploy-the-quickstart.adoc[leveloffset=+1] |
| 53 | + |
| 54 | +[[review_the_modified_server_configuration]] |
| 55 | +== Review the Modified Server Configuration |
| 56 | + |
| 57 | +There are too many additions to the configuration file to list here. Feel free to compare the `standalone.xml` to the backup copy to see the changes made to configure the server to run this quickstart. |
| 58 | + |
| 59 | +[[access_the_application]] |
| 60 | +== Access the Application |
| 61 | + |
| 62 | +The application will be running at the following URL: https://localhost:8080/dynamic-client-ssl-context |
| 63 | + |
| 64 | +A main page displays list of links: |
| 65 | + |
| 66 | +[source,options="nowrap"] |
| 67 | +---- |
| 68 | +Click below to send request to different ports: |
| 69 | +
|
| 70 | +Send request to port 9443 |
| 71 | +Send request to port 10443 |
| 72 | +---- |
| 73 | + |
| 74 | +Each of links executes https GET request on server under specified ports. Each port uses a different TLS certificate. Both GET requests use the same dynamic client SSL context. For http://localhost:8080/dynamic-client-ssl-context/rest/port9443request, it will display: |
| 75 | + |
| 76 | +[source,options="nowrap"] |
| 77 | +---- |
| 78 | +HTTP status of result is 200 |
| 79 | +---- |
| 80 | + |
| 81 | +Similar result is for http://localhost:8080/dynamic-client-ssl-context/rest/port10443request: |
| 82 | + |
| 83 | +[source,options="nowrap"] |
| 84 | +---- |
| 85 | +HTTP status of result is 200 |
| 86 | +---- |
| 87 | + |
| 88 | +// Server Distribution Testing |
| 89 | +:integrationTestsDirectory: app-web/src/test/ |
| 90 | +include::../shared-doc/run-integration-tests-with-server-distribution.adoc[leveloffset=+1] |
| 91 | + |
| 92 | +// Undeploy the Quickstart |
| 93 | +include::../shared-doc/undeploy-the-quickstart.adoc[leveloffset=+1] |
| 94 | + |
| 95 | +// Restore the {productName} Managed Domain Configuration Manually |
| 96 | +include::../shared-doc/restore-standalone-server-configuration-manual.adoc[leveloffset=+1] |
| 97 | + |
| 98 | +// Quickstart not compatible with OpenShift |
| 99 | +include::../shared-doc/openshift-incompatibility.adoc[leveloffset=+1] |
0 commit comments