davsclaus opened a new pull request, #27005: URL: https://github.com/apache/camel/pull/27005
Fixes [CAMEL-25102](https://issues.apache.org/jira/browse/CAMEL-25102): bugs found in a deep review of the JSSE utility (`SSLContextParameters`) and the `camel.ssl.*` configuration of camel-main. ## Fixed 1. **A filter with only exclude patterns included nothing, so every TLS handshake failed.** This affected `camel.ssl.namedGroupsExclude = X25519MLKEM768`, the documented way to disable the post-quantum named groups, and `camel.ssl.cipherSuitesExclude`. Such a filter now includes all the other values; a filter with no patterns at all still includes nothing. 2. **A signature schemes filter set an empty list on JVMs that do not provide their default signature schemes** (JDK 25 and older return `null`), so every handshake failed. The filter is now skipped with a WARN, and the JVM defaults are used. The existing test asserted the empty list; it is updated. 3. **SNI host names of the client parameters were set on `SSLSocket` but not on `SSLEngine`**, so engine-based clients (such as camel-netty) sent no SNI. 4. **Property placeholders in filter patterns were not resolved when configured from Java.** The XML factory beans already resolved them. 5. **SNI host names could not use property placeholders.** 6. **Auto-configured post-quantum named groups stayed on the `SSLContextParameters` instance when creating the `SSLContext` failed.** They are now reset in a `finally` block. 7. **`clientAuthentication` is now case-insensitive.** 8. **`camel.ssl.trustStore=#bean:name` failed**, because the `KeyStore` bean was turned into a String when the properties were bound. 9. **`camel.ssl.*` with only a trust store (or `trustAllCertificates`) created no global SSL configuration**, such as for a client that must trust a private certificate authority. 10. **Documentation:** - the default protocol is TLSv1.3; - `createSSLContext(camelContext)` needs the CamelContext; - the `camel.ssl.signatureSchemes` example now uses valid JSSE names; - the doc now explains exclude-only filters and when the signature schemes filter cannot be applied. The upgrade guide covers 1, 2 and 3. ## Not changed - `toString()` does not include named groups, signature schemes and their filters. - `SSLConfigurationProperties` has no `secureSocketProtocols` list or filter, no separate key password and no `trustStoreType`. ## Tests - **New tests:** `JsseEdgeCasesTest` (camel-core) covers exclude-only filters, placeholders in filter patterns, SNI on `SSLEngine` with placeholders, and case-insensitive client authentication. `MainSSLTrustStoreTest` (camel-main) covers `#bean:` trust stores and a trust store without a key store. - **Updated test:** `SSLContextParametersTest.testSignatureSchemesFilter`. - **Without the fix:** all of the new and changed tests fail. - **Full suites:** camel-core, camel-main and all their upstream modules pass, built with `-am`. _Claude Code on behalf of Claus Ibsen_ 🤖 Generated with [Claude Code](https://claude.com/claude-code) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
