Spring cloud gateway resource server: No subject alternative names present

Viewed 417

Our spring cloud gateway is configured as a resource server for token validation in keycloak and access control, our keycloak instance is running on https (for ldap connection), and when I try to send request to the gateway with the token, I get the error: `Caused by: javax.net.ssl.SSLHandshakeException: No subject alternative names'.

What options do I have to disable certificate and subject alternative names checking during development for keycloak authentication? Thanks for any recommendations.

1 Answers

Ok,i forgot about this problem but i have simple solution now. Look like a dev solution only.

@Configuration
@Slf4j
@ConditionalOnProperty("spring.security.oauth2.resourceserver.jwt.jwk-set-uri")
public class SslResolverConfig {

  @Value("${spring.security.oauth2.resourceserver.jwt.jwk-set-uri}")
  private String issuerUri;

  @Bean
  public ReactiveJwtDecoder reactiveJwtDecoder() {
    log.debug("ISSUE uri {}", issuerUri);
    var jvmBlockingResolver = createHttpClient();
    var connector = new ReactorClientHttpConnector(jvmBlockingResolver);
    var webClient = WebClient
        .builder()
        .clientConnector(connector)
        .build();
    return NimbusReactiveJwtDecoder
        .withJwkSetUri(issuerUri)
        .webClient(webClient)
        .build();
  }

  @SneakyThrows
  public HttpClient createHttpClient() {
    TrustManager[] trustAllCerts = new TrustManager[]{new X509TrustManager() {
      public java.security.cert.X509Certificate[] getAcceptedIssuers() {
        return null;
      }

      public void checkClientTrusted(X509Certificate[] certs, String authType) {
      }

      public void checkServerTrusted(X509Certificate[] certs, String authType) {
      }
    }
    };

    SSLContext sc = SSLContext.getInstance("SSL");
    sc.init(null, trustAllCerts, new java.security.SecureRandom());
    HttpsURLConnection.setDefaultSSLSocketFactory(sc.getSocketFactory());

    SslContext sslContext = SslContextBuilder
        .forClient()
        .trustManager(InsecureTrustManagerFactory.INSTANCE)
        .build();
    return HttpClient.create()
        .secure(t -> t.sslContext(sslContext))
        .wiretap("LoggingFilter", LogLevel.INFO, AdvancedByteBufFormat.TEXTUAL);
  }
}
Related