diff --git a/docs/modules/ROOT/pages/spring-cloud-gateway-server-webflux/tls-and-ssl.adoc b/docs/modules/ROOT/pages/spring-cloud-gateway-server-webflux/tls-and-ssl.adoc index ab1f0e682..65d3b5ce6 100644 --- a/docs/modules/ROOT/pages/spring-cloud-gateway-server-webflux/tls-and-ssl.adoc +++ b/docs/modules/ROOT/pages/spring-cloud-gateway-server-webflux/tls-and-ssl.adoc @@ -68,3 +68,33 @@ spring: close-notify-flush-timeout-millis: 3000 close-notify-read-timeout-millis: 0 ---- + +[[ssl-provider]] +== SSL Provider and netty-tcnative + +Both the gateway server and the gateway HTTP client use Reactor Netty for TLS, so the SSL +provider is chosen by Reactor Netty and not by the gateway itself. +If `netty-tcnative` is on the classpath, the native `OPENSSL` provider is used. +Otherwise, the `JDK` provider is used. +No gateway-specific configuration is required to enable it: + +.pom.xml +[source,xml] +---- + + io.netty + netty-tcnative-boringssl-static + +---- + +The version is managed by the Netty BOM that Spring Boot imports, so it can be omitted. +To force the JDK provider even when `netty-tcnative` is available, set +`-Dio.netty.handler.ssl.noOpenSsl=true`. + +To verify which engine has been selected at runtime, enable `DEBUG` logging for +`io.netty.handler.ssl.OpenSsl` and `reactor.netty.tcp.SslProvider`. + +TIP: See the Reactor Netty reference documentation for +https://projectreactor.io/docs/netty/release/reference/http-server.html#ssl-and-tls[server] +and https://projectreactor.io/docs/netty/release/reference/http-client.html#ssl-and-tls[client] +SSL and TLS configuration details.