From 44e53d45f67b5fe9b150ecb0f0c5b60dd978b5b9 Mon Sep 17 00:00:00 2001 From: Gaurav K Ohri Date: Sun, 13 Sep 2026 12:05:53 -0500 Subject: [PATCH] Document netty-tcnative SSL provider support Adds an SSL Provider section to the webflux server TLS and SSL docs explaining that Reactor Netty selects the native OPENSSL provider when netty-tcnative is on the classpath, how to force the JDK provider, how to verify the engine via debug logging, and links to the current Reactor Netty server/client SSL and TLS docs. Fixes gh-373 Signed-off-by: Gaurav K Ohri --- .../tls-and-ssl.adoc | 30 +++++++++++++++++++ 1 file changed, 30 insertions(+) diff --git a/docs/modules/ROOT/pages/spring-cloud-gateway-server-webflux/tls-and-ssl.adoc b/docs/modules/ROOT/pages/spring-cloud-gateway-server-webflux/tls-and-ssl.adoc index ab1f0e682b..65d3b5ce6d 100644 --- a/docs/modules/ROOT/pages/spring-cloud-gateway-server-webflux/tls-and-ssl.adoc +++ b/docs/modules/ROOT/pages/spring-cloud-gateway-server-webflux/tls-and-ssl.adoc @@ -68,3 +68,33 @@ spring: close-notify-flush-timeout-millis: 3000 close-notify-read-timeout-millis: 0 ---- + +[[ssl-provider]] +== SSL Provider and netty-tcnative + +Both the gateway server and the gateway HTTP client use Reactor Netty for TLS, so the SSL +provider is chosen by Reactor Netty and not by the gateway itself. +If `netty-tcnative` is on the classpath, the native `OPENSSL` provider is used. +Otherwise, the `JDK` provider is used. +No gateway-specific configuration is required to enable it: + +.pom.xml +[source,xml] +---- + + io.netty + netty-tcnative-boringssl-static + +---- + +The version is managed by the Netty BOM that Spring Boot imports, so it can be omitted. +To force the JDK provider even when `netty-tcnative` is available, set +`-Dio.netty.handler.ssl.noOpenSsl=true`. + +To verify which engine has been selected at runtime, enable `DEBUG` logging for +`io.netty.handler.ssl.OpenSsl` and `reactor.netty.tcp.SslProvider`. + +TIP: See the Reactor Netty reference documentation for +https://projectreactor.io/docs/netty/release/reference/http-server.html#ssl-and-tls[server] +and https://projectreactor.io/docs/netty/release/reference/http-client.html#ssl-and-tls[client] +SSL and TLS configuration details.