davsclaus opened a new pull request, #27010:
URL: https://github.com/apache/camel/pull/27010

   Fixes [CAMEL-25106](https://issues.apache.org/jira/browse/CAMEL-25106).
   
   When camel-kafka is configured with `sslContextParameters`, including global 
SSL with `useGlobalSslContextParameters`, two things went wrong:
   1. **The SSL endpoint options were ignored.** Since CAMEL-17615 the 
configuration used either the `sslContextParameters` or the endpoint options, 
not both, so `sslTruststoreLocation`, `sslTruststorePassword`, 
`sslEndpointAlgorithm` and the other `ssl*` options were dropped. The option's 
documentation says the `sslContextParameters` are applied *before* the other 
SSL endpoint options. For example, turning on global SSL for the component 
replaced a truststore configured on an endpoint.
   2. **`security.protocol` stayed `PLAINTEXT`**, the default, unless 
`securityProtocol` or `saslAuthType` was set. The `ssl.*` properties were set, 
but SSL was not used.
   
   ## Changes
   - **Precedence:** the `sslContextParameters` are applied first, then the SSL 
endpoint options. An endpoint option left at its default (such as 
`sslTruststoreType=JKS`) does not replace a value that came from the 
`sslContextParameters`.
   - **Security protocol:** when `sslContextParameters` is configured and 
`securityProtocol` is the default `PLAINTEXT`, `SSL` is used. An explicitly 
configured protocol such as `SASL_SSL` or `SASL_PLAINTEXT` is kept.
   
   The upgrade guide has an entry.
   
   ## Tests
   - **New `KafkaSslContextParametersTest`**, covering both producer and 
consumer properties:
     - `sslContextParameters` alone use `SSL` and keep the truststore type they 
configure;
     - endpoint SSL options override the `sslContextParameters`;
     - an explicit security protocol is kept.
   - **Without the fix:** the new tests fail.
   - **Unit tests:** the camel-kafka unit test suite passes. The 
container-based integration tests were not run.
   
   The change should be backported to the supported release lines (4.22.x and 
4.18.x).
   
   _Claude Code on behalf of Claus Ibsen_
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to