Connection DNS resolution and SSL validation after DBeaver 23.3 per-connection truststore change
25K reputation · 31 Jul 2022, 21:35 UTC
DBeaver delegates DNS lookups to the underlying JVM, which caches results according to the networkaddress.cache.ttl system property. The UI does not expose a runtime control to invalidate that cache for a specific connection.
Starting with DBeaver 23.3, a per-connection property useCustomTruststore allows distinct truststores per connection. The connection wizard supports selecting a custom truststore, but there is no documented per-connection setting to disable or adjust hostname verification. Hostname verification therefore remains tied to JVM-wide security settings.
With no built-in mechanism to flush DNS or refresh SSL session caches from within the client, the behavior for dynamic DNS updates and certificate rotations without restarting DBeaver is unclear.
Questions
Is there a supported way to refresh JVM DNS resolution for an existing DBeaver connection without restarting the application? Is hostname verification controllable per connection in DBeaver 23.3 and later, or only via global JVM properties? How does per-connection truststore handling interact with certificate rotation for an active connection?