Skip to content

Add TLS for the wire protocol and Studio - #19

Merged
venkat1701 merged 4 commits into
mainfrom
feat/tls
Oct 4, 2026
Merged

venkat1701 merged 4 commits into
mainfrom
feat/tls

Conversation

@venkat1701

Copy link
Copy Markdown
Collaborator

Closes #5

Turning on tls makes both listeners use TLS with the same certificate: the wire protocol on its usual port and Studio over HTTPS.

New settings:

  • tls (off by default)
  • tls_certificate_file, a PEM chain
  • tls_key_file, an unencrypted PKCS#8 PEM key (EC, RSA or Ed25519)
  • tls_ca_file on the client side

hstore connect verifies the certificate and host name. It trusts tls_ca_file first, then the server's own certificate, then the system store, so self-signed setups work without extra steps. hstore ping skips the host name check, which keeps the Docker healthcheck working against 127.0.0.1. Studio sets Secure on its cookie whenever it serves HTTPS.

While testing I found that a plaintext client on a TLS port hung forever: the client waited for the banner and the server waited for a ClientHello. Both sides now give up after 10 seconds, and the server logs it.

Tested:

  • wireProtocolRunsOverTls checks a trusted client, a client using the system store (rejected) and a plaintext client (fails within the timeout).
  • tlsWithoutACertificateIsRejectedAtStartup checks startup with tls on and no certificate.
  • studioServesHttpsWithSecureCookies checks Studio over HTTPS and the Secure cookie.
  • The test certificate is a self-signed localhost/127.0.0.1 fixture under server/src/test/resources/tls.
  • Full ./mvnw install is green.
  • I also built the native image and checked ping, connect and Studio over TLS, plus the plaintext timeout, by hand.

tls, tls_certificate_file and tls_key_file configure the server side.
tls_ca_file tells clients what to trust, falling back to the server's own
certificate and then the system store.
The wire listener and Studio share one TLS context, and Studio marks its
session cookie Secure. The server finishes the handshake before sending
the banner and gives up after 10 seconds, and clients bound their connect
and banner read the same way, so a plaintext client on a TLS port no
longer hangs either side.
@venkat1701
venkat1701 merged commit 2dfc92b into main Oct 4, 2026
@venkat1701
venkat1701 deleted the feat/tls branch October 4, 2026 08:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

TLS for the wire protocol and Studio

1 participant