Skip to content

[CALCITE-5896] Document TLS client certificate JDBC URL options - #324

Open
akashchamp wants to merge 1 commit into
apache:mainfrom
akashchamp:CALCITE-5896
Open

akashchamp wants to merge 1 commit into
apache:mainfrom
akashchamp:CALCITE-5896

Conversation

@akashchamp

@akashchamp akashchamp commented Sep 24, 2026 •

Copy link
Copy Markdown

What

Documents the keystore, keystore_password, and key_password JDBC URL
properties on the client reference page.

Why

CALCITE-5896: the
client reference documents truststore, truststore_password, and
keystore_type (used to verify the server's certificate), but never
documented keystore, keystore_password, or key_password (used to
supply the client's own certificate/private key for mutual TLS). These
three properties have existed in BuiltInConnectionProperty since
CALCITE-2285 and are consumed by
CommonsHttpClientPoolCache#loadKeyStore via
SSLContextBuilder#loadKeyMaterial, but a user reading the reference page
has no way to discover them.

Change

Adds three definition-list entries to site/_docs/client_reference.md,
placed right after the existing keystore_type entry (matching the
declaration order in BuiltInConnectionProperty) and mirroring the
wording/format of the adjacent truststore / truststore_password
entries:

  • keystore
  • keystore_password
  • key_password

No code changes; this is a pure documentation addition (1 file changed,
31 insertions, 0 deletions).

Verification

  • Confirmed the gap against the live published page and against
    BuiltInConnectionProperty.java, ConnectionConfig(Impl).java, and
    CommonsHttpClientPoolCache.java (where keystore / keystore_password
    / key_password are actually consumed).
  • Rendered the edited section with kramdown (the markdown engine this
    Jekyll site uses, per site/_config.yml) to confirm the new entries
    produce the same <dt>/<dd> structure as their siblings, and that the
    new anchors (#keystore, #keystore_password, #key_password) are
    unique and resolve correctly.
  • Checked the whole page for anchor-name collisions: none.

@F21

F21 commented Sep 24, 2026

Copy link
Copy Markdown
Member

@akashchamp can you please request an account at https://issues.apache.org/ , so we can assign CALCITE-5896 to you?

The client reference page documents truststore, truststore_password,
and keystore_type, which cover server-certificate verification, but
omits the keystore, keystore_password, and key_password JDBC URL
properties. CommonsHttpClientPoolCache uses these three to load the
client's own key material (loadKeyMaterial) for mutual TLS (mTLS)
client certificate authentication, and BuiltInConnectionProperty has
declared them since CALCITE-2285.

Add entries for keystore, keystore_password, and key_password,
mirroring the format of the existing truststore/keystore_type
entries.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants