davsclaus opened a new pull request, #27011:
URL: https://github.com/apache/camel/pull/27011

   Fixes [CAMEL-25107](https://issues.apache.org/jira/browse/CAMEL-25107).
   
   When the named groups or signature schemes configured on 
`SSLContextParameters` contained a duplicate or blank value, the whole 
configured list was silently ignored and the JVM's default named groups were 
used instead.
   
   `BaseSSLContextParameters` calls `SSLParameters.setNamedGroups` and 
`setSignatureSchemes` using reflection, because they don't exist on JDK 17. The 
JDK rejects a list with a blank or duplicate value, and those calls ignored the 
exception, so nothing was configured and nothing was logged. For example, 
`[secp384r1, secp384r1]` or `[secp384r1, ""]` ended up with all of the JVM's 
default groups.
   
   This happens easily from camel-main, because `camel.ssl.namedGroups` and 
`camel.ssl.signatureSchemes` are split on commas without trimming:
   - `secp384r1,,x25519` has a blank value, so the whole setting is ignored;
   - a copy/paste duplicate also ignores the whole setting;
   - `secp384r1, x25519` (a space after the comma) gives the unknown name `" 
x25519"`.
   
   ## Changes
   - **Clean the values:** trim them, and remove blank and duplicate values 
while keeping the order.
   - **Fail clearly:** if the JVM still rejects the values, fail with an error 
naming them, instead of silently using the JVM defaults.
   - **Warn on older JVMs:** log a WARN once when named groups or signature 
schemes are configured but the JVM does not support them (JDK 17). Before, they 
were skipped without a warning.
   
   ## Tests
   - **New `SSLContextParametersNamedGroupsListTest`:** named groups and 
signature schemes that contain duplicate, blank and untrimmed values are 
configured on the `SSLEngine` as the cleaned list. The test fails without the 
fix: the JVM defaults were used for the named groups, and the signature schemes 
were not set at all.
   - **Existing tests:** the JSSE tests in camel-core and the camel-main SSL 
tests pass.
   
   The change should be backported to the supported release lines (4.22.x and 
4.18.x).
   
   _Claude Code on behalf of Claus Ibsen_
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to