davsclaus opened a new pull request, #27007: URL: https://github.com/apache/camel/pull/27007
Fixes [CAMEL-25103](https://issues.apache.org/jira/browse/CAMEL-25103). The Vert.x-based components (camel-platform-http-vertx, camel-vertx-http, camel-vertx-websocket) configure Vert.x from `SSLContextParameters` in `VertxHelper.setupSSLOptions`, but only copy the key managers and trust managers. Two other settings were not applied: - the `clientAuthentication` of the server parameters, so the Vert.x server kept its default of no client authentication; - the configured cipher suites and secure socket protocols. This also affects the camel-main embedded HTTP server and management server, which use global SSL (`camel.ssl.*`). ## Changes - **Client authentication:** for Vert.x server options, `clientAuthentication` (NONE/WANT/REQUIRE) is mapped to Vert.x `ClientAuth` (NONE/REQUEST/REQUIRED). - **Cipher suites and protocols:** when configured, as explicit lists or include/exclude filters, the enabled values are computed by `SSLContextParameters` and applied to the Vert.x options. ## Tests - **New tests in `VertxPlatformHttpEngineTest`** (both fail without the fix): - with `REQUIRE`, a client without a certificate is rejected; - a server restricted to one cipher suite rejects a client that only offers another one. The existing SSL tests did not catch the missing client authentication because their client always sends a certificate. - **Test suites:** - camel-vertx-common, camel-vertx-http, camel-vertx-websocket and camel-platform-http-main pass. - camel-platform-http-vertx passes except `VertxPlatformHttpNoBodyHandlerTest`, which also fails locally without this change. It does not use SSL. The change should be backported to the supported release lines (4.22.x and 4.18.x). _Claude Code on behalf of Claus Ibsen_ 🤖 Generated with [Claude Code](https://claude.com/claude-code) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
