From 0b846fb78e9bf21875b8b9b16d07be4b4beeaba0 Mon Sep 17 00:00:00 2001
From: Valery Kharseko <vharseko@3a-systems.ru>
Date: Mon, 28 Sep 2026 12:53:31 +0000
Subject: [PATCH] [#1109] Keep a connection handler listening when a change to it is rejected (#1110)

---
 opendj-server-legacy/src/main/java/org/forgerock/opendj/reactive/LDAPConnectionHandler2.java |   29 +++++++++++++++++++++--------
 1 files changed, 21 insertions(+), 8 deletions(-)

diff --git a/opendj-server-legacy/src/main/java/org/forgerock/opendj/reactive/LDAPConnectionHandler2.java b/opendj-server-legacy/src/main/java/org/forgerock/opendj/reactive/LDAPConnectionHandler2.java
index 482b318..5f40bd1 100644
--- a/opendj-server-legacy/src/main/java/org/forgerock/opendj/reactive/LDAPConnectionHandler2.java
+++ b/opendj-server-legacy/src/main/java/org/forgerock/opendj/reactive/LDAPConnectionHandler2.java
@@ -316,7 +316,7 @@
     private void configureSSL(LDAPConnectionHandlerCfg config) throws DirectoryException {
         protocol = config.isUseSSL() ? "LDAPS" : "LDAP";
         if (config.isUseSSL() || config.isAllowStartTLS()) {
-            sslContext = createSSLContext(config);
+            sslContext = createSSLContext(config, true);
             sslEngine = createSSLEngine(config, sslContext);
         } else {
             sslContext = null;
@@ -581,7 +581,7 @@
         // Check that the SSL configuration is valid.
                 && (config.isUseSSL() || config.isAllowStartTLS())) {
             try {
-                createSSLEngine(config, createSSLContext(config));
+                createSSLEngine(config, createSSLContext(config, false));
             } catch (DirectoryException e) {
                 logger.traceException(e);
 
@@ -937,26 +937,39 @@
         }
     }
 
-    private void disableAndWarnIfUseSSL(LDAPConnectionHandlerCfg config) {
-        if (config.isUseSSL()) {
+    private void disableAndWarnIfUseSSL(LDAPConnectionHandlerCfg config, boolean forUse) {
+        if (forUse && config.isUseSSL()) {
             logger.warn(INFO_DISABLE_CONNECTION, friendlyName);
             enabled = false;
         }
     }
 
-    private SSLContext createSSLContext(LDAPConnectionHandlerCfg config) throws DirectoryException {
+    /**
+     * Creates the SSL context for the provided configuration.
+     *
+     * @param config
+     *            the configuration to create the SSL context for
+     * @param forUse
+     *            {@code true} when the handler is going to use the SSL context, at its start or when a change is
+     *            applied, so that an SSL handler without a usable key is disabled; {@code false} when the SSL context
+     *            only checks a proposed configuration, which must leave the running handler as it is
+     * @return the SSL context
+     * @throws DirectoryException
+     *             if the SSL context cannot be created
+     */
+    private SSLContext createSSLContext(LDAPConnectionHandlerCfg config, boolean forUse) throws DirectoryException {
         try {
             DN keyMgrDN = config.getKeyManagerProviderDN();
             final ServerContext serverContext = DirectoryServer.getInstance().getServerContext();
             KeyManagerProvider<?> keyManagerProvider = serverContext.getKeyManagerProvider(keyMgrDN);
             if (keyManagerProvider == null) {
                 logger.error(ERR_NULL_KEY_PROVIDER_MANAGER, keyMgrDN, friendlyName);
-                disableAndWarnIfUseSSL(config);
+                disableAndWarnIfUseSSL(config, forUse);
                 keyManagerProvider = new NullKeyManagerProvider();
                 // The SSL connection is unusable without a key manager provider
             } else if (!keyManagerProvider.containsAtLeastOneKey()) {
                 logger.error(ERR_INVALID_KEYSTORE, friendlyName);
-                disableAndWarnIfUseSSL(config);
+                disableAndWarnIfUseSSL(config, forUse);
             }
 
             final SortedSet<String> aliases = new TreeSet<>(config.getSSLCertNickname());
@@ -973,7 +986,7 @@
                 }
 
                 if (aliases.isEmpty()) {
-                    disableAndWarnIfUseSSL(config);
+                    disableAndWarnIfUseSSL(config, forUse);
                 }
                 keyManagers = SelectableCertificateKeyManager.wrap(keyManagerProvider.getKeyManagers(), aliases,
                         friendlyName);

--
Gitblit v1.10.0