Skip to content

[deps] update jruby-openssl to 0.11.0#6909

Merged
enebo merged 2 commits intojruby:jruby-9.2from
kares:jossl-0.11_9.2
Oct 27, 2021
Merged

[deps] update jruby-openssl to 0.11.0#6909
enebo merged 2 commits intojruby:jruby-9.2from
kares:jossl-0.11_9.2

Conversation

@kares
Copy link
Member

@kares kares commented Oct 26, 2021

to properly support alt-chain TLS certificate verifications

old verify behavior can be forced using a system property:
-Djruby.openssl.x509.store.verify=legacy

details at failing verification at #6872

to properly support alt-chain TLS certificate verifications

old verify behavior can be forced using a system property:
`-Djruby.openssl.x509.store.verify=legacy`
@kares kares added this to the JRuby 9.2.20.0 milestone Oct 26, 2021
@headius
Copy link
Member

headius commented Oct 26, 2021

Appears that the jars grew as a result of this update. Double check that the increase is expected and update the check-versions.sh script.

due jruby-openssl 0.10.5 -> 0.11.0 growing by 1.5MB
@kares
Copy link
Member Author

kares commented Oct 26, 2021

right, it's justified and 9.3 (master) actually has these adjusted to account for jossl 0.10.7,
which due a BC update grow by 1.5MB, 9.2 was on jossl 0.10.5 so the size update is expected ...

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Jruby does not support the "old" LetsEncrypt chain after DST Root CA X3 has expired

3 participants