davsclaus opened a new pull request, #27009: URL: https://github.com/apache/camel/pull/27009
Fixes [CAMEL-25105](https://issues.apache.org/jira/browse/CAMEL-25105). A camel-netty or camel-netty-http consumer that uses `sslContextParameters` did not apply the client authentication from its server parameters: `SSLContextServerParameters.clientAuthentication`, or `camel.ssl.clientAuthentication` with global SSL. The `SSLEngine` created from the `sslContextParameters` is configured correctly, for example with `REQUIRE`. The consumer then called `engine.setNeedClientAuth(needClientAuth)` with the endpoint option, which is `false` by default, and that turned client authentication off, including `WANT`. ## Change `setNeedClientAuth(true)` is now called only when the `needClientAuth` option is enabled. Otherwise the engine keeps the client authentication from the `sslContextParameters`. Without `sslContextParameters` nothing changes, because the engine's default is already no client authentication. The change is in three classes: - `DefaultServerInitializerFactory` (camel-netty) - `HttpServerInitializerFactory` and `HttpServerSharedInitializerFactory` (camel-netty-http) The upgrade guide has an entry. ## Tests - **New `NettySSLContextParametersClientAuthTest`** uses a server whose `sslContextParameters` require client authentication, with `needClientAuth` not enabled: - a client with a certificate succeeds; - a client without a certificate is rejected. - **Without the fix:** the client without a certificate got a reply. - **Full suites:** camel-netty and camel-netty-http pass. The change should be backported to the supported release lines (4.22.x and 4.18.x). _Claude Code on behalf of Claus Ibsen_ 🤖 Generated with [Claude Code](https://claude.com/claude-code) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
