Skip to content

Commit e28f849

Browse files
committed
Clearify when it's safe to set callbacks in SSLContext javadocs
Motivation: We should make it clear when it safe to call the various SSLContext.set*(...) methods that configure callbacks to use. Modifications: - Enhance javadocs Result: Ensure people are aware that these callbacks need to be configure before the SSLContext is used to create SSL objects
1 parent 9c01de6 commit e28f849

1 file changed

Lines changed: 18 additions & 1 deletion

File tree

‎openssl-classes/src/main/java/io/netty/internal/tcnative/SSLContext.java‎

Lines changed: 18 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -500,6 +500,9 @@ public static void setSessionTicketKeys(long ctx, SessionTicketKey[] keys) {
500500
* Allow to hook {@link CertificateVerifier} into the handshake processing.
501501
* This will call {@code SSL_CTX_set_cert_verify_callback} and so replace the default verification
502502
* callback used by openssl
503+
* <p>
504+
* <strong>Important: This method must only be called before any SSL object was created and used
505+
* that belongs to this context. Failing to do so results in undefined behaviour.</strong>
503506
* @param ctx Server or Client context to use.
504507
* @param verifier the verifier to call during handshake.
505508
*/
@@ -509,6 +512,9 @@ public static void setSessionTicketKeys(long ctx, SessionTicketKey[] keys) {
509512
* Allow to hook {@link CertificateRequestedCallback} into the certificate choosing process.
510513
* This will call {@code SSL_CTX_set_client_cert_cb} and so replace the default verification
511514
* callback used by openssl
515+
* <p>
516+
* <strong>Important: This method must only be called before any SSL object was created and used
517+
* that belongs to this context. Failing to do so results in undefined behaviour.</strong>
512518
* @param ctx Server or Client context to use.
513519
* @param callback the callback to call during certificate selection.
514520
* @deprecated use {@link #setCertificateCallback(long, CertificateCallback)}
@@ -520,6 +526,9 @@ public static void setSessionTicketKeys(long ctx, SessionTicketKey[] keys) {
520526
* Allow to hook {@link CertificateCallback} into the certificate choosing process.
521527
* This will call {@code SSL_CTX_set_cert_cb} and so replace the default verification
522528
* callback used by openssl
529+
* <p>
530+
* <strong>Important: This method must only be called before any SSL object was created and used
531+
* that belongs to this context. Failing to do so results in undefined behaviour.</strong>
523532
* @param ctx Server or Client context to use.
524533
* @param callback the callback to call during certificate selection.
525534
*/
@@ -529,6 +538,9 @@ public static void setSessionTicketKeys(long ctx, SessionTicketKey[] keys) {
529538
* Allow to hook {@link SniHostNameMatcher} into the sni processing.
530539
* This will call {@code SSL_CTX_set_tlsext_servername_callback} and so replace the default
531540
* callback used by openssl
541+
* <p>
542+
* <strong>Important: This method must only be called before any SSL object was created and used
543+
* that belongs to this context. Failing to do so results in undefined behaviour.</strong>
532544
* @param ctx Server or Client context to use.
533545
* @param matcher the matcher to call during sni hostname matching.
534546
*/
@@ -541,6 +553,9 @@ public static void setSessionTicketKeys(long ctx, SessionTicketKey[] keys) {
541553
* <p>
542554
* <strong>Warning:</strong> The log output will contain secret key material, and can be used to decrypt
543555
* TLS sessions! The log output should be handled with the same care given to the private keys.
556+
* <p>
557+
* <strong>Important: This method must only be called before any SSL object was created and used
558+
* that belongs to this context. Failing to do so results in undefined behaviour.</strong>
544559
* @param ctx Server or Client context to use.
545560
* @param callback the callback to call when delivering debug output.
546561
* @return {@code true} if the key-log callback was assigned,
@@ -722,7 +737,9 @@ public static void setPrivateKeyMethod(long ctx, AsyncSSLPrivateKeyMethod method
722737

723738
/**
724739
* Set the {@link SSLSessionCache} that will be used if session caching is enabled.
725-
*
740+
* <p>
741+
* <strong>Important: This method must only be called before any SSL object was created and used
742+
* that belongs to this context. Failing to do so results in undefined behaviour.</strong>
726743
* @param ctx context to use.
727744
* @param cache cache to use for the given context.
728745
*/

0 commit comments

Comments
 (0)