summaryrefslogtreecommitdiffstats
path: root/controller-api
diff options
context:
space:
mode:
authorBjørn Christian Seime <bjorncs@oath.com>2018-01-04 15:54:49 +0100
committerBjørn Christian Seime <bjorncs@oath.com>2018-01-04 15:54:49 +0100
commit989d5df90b92ba3fd667c568cf61c047b6b74ad2 (patch)
treea5b603e825adc68171278328680f319f0b0eabed /controller-api
parentf5f5222460ff5a65ecd7c2da81fecc049a0faecc (diff)
Use httpclient version matching zts-client
Also remove hostnameverifier adapter that is no longer needed.
Diffstat (limited to 'controller-api')
-rw-r--r--controller-api/src/main/java/com/yahoo/vespa/hosted/controller/api/integration/athenz/AthenzIdentityVerifier.java6
1 files changed, 1 insertions, 5 deletions
diff --git a/controller-api/src/main/java/com/yahoo/vespa/hosted/controller/api/integration/athenz/AthenzIdentityVerifier.java b/controller-api/src/main/java/com/yahoo/vespa/hosted/controller/api/integration/athenz/AthenzIdentityVerifier.java
index 6f8ebc4c5db..764ba9c2104 100644
--- a/controller-api/src/main/java/com/yahoo/vespa/hosted/controller/api/integration/athenz/AthenzIdentityVerifier.java
+++ b/controller-api/src/main/java/com/yahoo/vespa/hosted/controller/api/integration/athenz/AthenzIdentityVerifier.java
@@ -29,16 +29,12 @@ public class AthenzIdentityVerifier implements HostnameVerifier {
public boolean verify(String hostname, SSLSession session) {
try {
X509Certificate cert = (X509Certificate) session.getPeerCertificates()[0];
- return isTrusted(AthenzUtils.createAthenzIdentity(cert));
+ return allowedIdentities.contains(AthenzUtils.createAthenzIdentity(cert));
} catch (SSLPeerUnverifiedException e) {
log.log(Level.WARNING, "Unverified client: " + hostname);
return false;
}
}
- public boolean isTrusted(AthenzIdentity identity) {
- return allowedIdentities.contains(identity);
- }
-
}