We used to Weblogic 12c servers on old java versions (1.8.0_51). After upgrading to 1.8.0_271, we have an intermittent issue: after working fine for a few minutes, TLS handshakes incoming to Weblogic fail.
The observed behaviour is as follows:
Client --[TCP SYN]--> Weblogic
Weblogic --[TCP SYN, ACK]--> Client
Client --[TCP ACK]--> Weblogic
Client --[Client Hello]--> Weblogic
Weblogic --[TCP FIN, ACK]--> Client
The handshake is being made using TLS 1.3.
This seem very unusual. I read through RFC 8446 (The Transport Layer Security (TLS) Protocol Version 1.3), and I was not able to find any reason why the server would close the TCP connection without sending an alert or a close_notify first. I'd even say that, from my understanding, the JVM behaviour is non-compliant:
Each party MUST send a "close_notify" alert before closing its write
side of the connection, unless it has already sent some error alert.
Going back to Java 1.8.0_51 is fixing the issue.
We have this issue on both Linux and Solaris servers, and we see this issue when doing tests both remotely and locally (on the CLI of the server, using openssl s_client). So there is no way that a firewall, WAF, IPS or anything else could cause this issue.