This example demonstrates how to use TLS (based on X.509 certificates) in Dubbo-Go and Dubbo-Java to enable encrypted communication and/or mutual authentication between a client and a server. More importantly, this example showcases the cross-language interoperability between Dubbo-Go and Dubbo-Java—through the Triple protocol and Protobuf serialization, a Go client can seamlessly call a Java server, and a Java client can call a Go server. The example includes client and server sample programs for both Go and Java, as well as scripts for generating test certificates using X.509.
greet servicex509/create.sh uses OpenSSL).Navigate to the x509 directory and run the certificate generation script:
On Unix-based systems, execute the following command:
cd tls/x509 && ./create.sh
On Windows, if OpenSSL or Bash is not installed, you can run the script using WSL/Git Bash or manually generate the certificates using OpenSSL following the configuration in x509/openssl.cnf.
The generated certificates will be stored in the x509/ directory, including:
server_ca_*.pemclient_ca_*.pemserver{1,2}_*.pemclient{1,2}_*.pemIn the tls directory, run the following command to start the Go server:
go run ./go-server/cmd
The server will load the server certificates and CA from the x509/ directory and listen on the address specified in the configuration. If you need to customize the configuration, please modify the server program or the relevant parts in the source code.
In another terminal in the tls directory, run the following command to start the Go client:
go run ./go-client/cmd
The client will use the certificates from the x509/ directory to establish a TLS connection with the server and invoke the greet service.
This demonstrates interoperability between Dubbo-Go and Dubbo-Java using the Triple protocol over TLS.
In the tls directory, navigate to the java-server subdirectory and start the Maven project:
cd ./java-server mvn clean compile mvn exec:java -Dexec.mainClass="org.apache.dubbo.samples.tls.provider.TlsTriProvider"
The Java server will start on port 20000 using TLS with the certificates from x509/server2_cert.pem and x509/server2_key.pem.
In another terminal, in the tls directory, run the Go client:
go run ./client/cmd
The Go client will connect to the Java server via TLS and invoke the greet service. You should see output like:
Greet response: hello world from Java provider
This option demonstrates the reverse interoperability—a Java client calling a Go server.
In the tls directory, run the following command to start the Go server:
go run ./go-server/cmd
The Go server will start on port 20000 with TLS encryption enabled.
In another terminal, in the tls directory, navigate to the java-client subdirectory and start the Maven project:
cd ./java-client mvn clean compile mvn exec:java -Dexec.mainClass="org.apache.dubbo.samples.tls.consumer.TlsTriProtoConsumer" # To customize the target host and TLS authority (SNI), add: -Dtls.host=127.0.0.1 -Dtls.authority=dubbogo.test.example.com
The Java client will connect to the Go server via TLS and invoke the greet service. You should see output like:
Greet response: hello world
This example demonstrates cross-language interoperability between Dubbo-Go and Dubbo-Java frameworks:
proto/greet.proto, code is generated for both Go and Javatls/go-server/cmd/main.go and tls/go-client/cmd/main.go to understand the specific behavior and available command-line parameters.create.sh script may require WSL/Git Bash or manually running OpenSSL commands.