This is an automated email from the ASF dual-hosted git repository.

gnodet pushed a commit to branch camel-4.22.x
in repository https://gitbox.apache.org/repos/asf/camel.git


The following commit(s) were added to refs/heads/camel-4.22.x by this push:
     new 452807d00ce1 [backport camel-4.22.x] CAMEL-25107: camel-core - 
SSLContextParameters ignores the configured named groups when the list has a 
duplicate or blank value (#27028)
452807d00ce1 is described below

commit 452807d00ce1579739881fcec0bef26a69b508e1
Author: Guillaume Nodet <[email protected]>
AuthorDate: Tue Sep 29 01:06:40 2026 +0200

    [backport camel-4.22.x] CAMEL-25107: camel-core - SSLContextParameters 
ignores the configured named groups when the list has a duplicate or blank 
value (#27028)
---
 .../support/jsse/BaseSSLContextParameters.java     | 54 ++++++++++++++----
 .../SSLContextParametersNamedGroupsListTest.java   | 66 ++++++++++++++++++++++
 2 files changed, 110 insertions(+), 10 deletions(-)

diff --git 
a/core/camel-api/src/main/java/org/apache/camel/support/jsse/BaseSSLContextParameters.java
 
b/core/camel-api/src/main/java/org/apache/camel/support/jsse/BaseSSLContextParameters.java
index 2d3e0a5ad909..689903e1c0a3 100644
--- 
a/core/camel-api/src/main/java/org/apache/camel/support/jsse/BaseSSLContextParameters.java
+++ 
b/core/camel-api/src/main/java/org/apache/camel/support/jsse/BaseSSLContextParameters.java
@@ -17,6 +17,7 @@
 package org.apache.camel.support.jsse;
 
 import java.io.IOException;
+import java.lang.reflect.InvocationTargetException;
 import java.lang.reflect.Method;
 import java.net.InetAddress;
 import java.net.ServerSocket;
@@ -28,9 +29,11 @@ import java.util.ArrayList;
 import java.util.Arrays;
 import java.util.Collection;
 import java.util.Collections;
+import java.util.LinkedHashSet;
 import java.util.LinkedList;
 import java.util.List;
 import java.util.Objects;
+import java.util.Set;
 import java.util.regex.Matcher;
 import java.util.regex.Pattern;
 
@@ -99,6 +102,9 @@ public abstract class BaseSSLContextParameters extends 
JsseParameters {
     private static final String SSL_SERVER_SOCKET_SIGNATURE_SCHEME_LOG_MSG
             = createSignatureSchemeLogMessage("SSLServerSocket");
 
+    private static volatile boolean namedGroupsNotSupportedWarned;
+    private static volatile boolean signatureSchemesNotSupportedWarned;
+
     // Reflection handles for JDK 19/20 SSLParameters methods (not available 
on JDK 17)
     private static final @Nullable Method GET_NAMED_GROUPS;
     private static final @Nullable Method SET_NAMED_GROUPS;
@@ -134,15 +140,42 @@ public abstract class BaseSSLContextParameters extends 
JsseParameters {
 
     private static void setNamedGroupsOnParams(SSLParameters params, String[] 
namedGroups) {
         if (SET_NAMED_GROUPS == null) {
+            if (!namedGroupsNotSupportedWarned) {
+                namedGroupsNotSupportedWarned = true;
+                LOG.warn("The named groups cannot be configured as this JVM 
does not support it (requires JDK 20 or newer)");
+            }
             return;
         }
+        invokeSetter(SET_NAMED_GROUPS, params, namedGroups, "named groups");
+    }
+
+    private static void invokeSetter(Method method, SSLParameters params, 
String[] values, String name) {
         try {
-            SET_NAMED_GROUPS.invoke(params, (Object) namedGroups);
-        } catch (Exception e) {
-            // ignore
+            method.invoke(params, (Object) values);
+        } catch (InvocationTargetException e) {
+            // the configured values must not be silently ignored (the JVM 
defaults would be used instead)
+            Throwable cause = e.getCause() != null ? e.getCause() : e;
+            throw new IllegalArgumentException(
+                    "Cannot configure the " + name + " " + 
Arrays.toString(values) + " due to: " + cause.getMessage(), cause);
+        } catch (IllegalAccessException e) {
+            throw new IllegalStateException(e);
         }
     }
 
+    /**
+     * Trims the values, and removes blank and duplicate values (keeping the 
order), as the JVM does not allow blank or
+     * duplicate named groups and signature schemes.
+     */
+    static List<String> normalizeValues(List<String> values) {
+        Set<String> answer = new LinkedHashSet<>();
+        for (String value : values) {
+            if (value != null && !value.isBlank()) {
+                answer.add(value.trim());
+            }
+        }
+        return new ArrayList<>(answer);
+    }
+
     private static String @Nullable [] 
getSignatureSchemesFromParams(SSLParameters params) {
         if (GET_SIGNATURE_SCHEMES == null) {
             return null;
@@ -156,13 +189,14 @@ public abstract class BaseSSLContextParameters extends 
JsseParameters {
 
     private static void setSignatureSchemesOnParams(SSLParameters params, 
String[] signatureSchemes) {
         if (SET_SIGNATURE_SCHEMES == null) {
+            if (!signatureSchemesNotSupportedWarned) {
+                signatureSchemesNotSupportedWarned = true;
+                LOG.warn(
+                        "The signature schemes cannot be configured as this 
JVM does not support it (requires JDK 19 or newer)");
+            }
             return;
         }
-        try {
-            SET_SIGNATURE_SCHEMES.invoke(params, (Object) signatureSchemes);
-        } catch (Exception e) {
-            // ignore
-        }
+        invokeSetter(SET_SIGNATURE_SCHEMES, params, signatureSchemes, 
"signature schemes");
     }
 
     /**
@@ -1190,7 +1224,7 @@ public abstract class BaseSSLContextParameters extends 
JsseParameters {
 
         Collection<String> filteredNamedGroups;
         if (enabledNamedGroups != null) {
-            filteredNamedGroups = new ArrayList<>(enabledNamedGroups);
+            filteredNamedGroups = normalizeValues(enabledNamedGroups);
         } else if (enabledNamedGroupsPatterns != null) {
             filteredNamedGroups = this.filter(
                     null, Arrays.asList(currentNamedGroups),
@@ -1227,7 +1261,7 @@ public abstract class BaseSSLContextParameters extends 
JsseParameters {
 
         Collection<String> filteredSignatureSchemes;
         if (enabledSignatureSchemes != null) {
-            filteredSignatureSchemes = new 
ArrayList<>(enabledSignatureSchemes);
+            filteredSignatureSchemes = 
normalizeValues(enabledSignatureSchemes);
         } else if (enabledSignatureSchemesPatterns != null) {
             filteredSignatureSchemes = this.filter(
                     null, Arrays.asList(currentSignatureSchemes),
diff --git 
a/core/camel-core/src/test/java/org/apache/camel/support/jsse/SSLContextParametersNamedGroupsListTest.java
 
b/core/camel-core/src/test/java/org/apache/camel/support/jsse/SSLContextParametersNamedGroupsListTest.java
new file mode 100644
index 000000000000..d5a67af1f8ed
--- /dev/null
+++ 
b/core/camel-core/src/test/java/org/apache/camel/support/jsse/SSLContextParametersNamedGroupsListTest.java
@@ -0,0 +1,66 @@
+/*
+ * Licensed to the Apache Software Foundation (ASF) under one or more
+ * contributor license agreements.  See the NOTICE file distributed with
+ * this work for additional information regarding copyright ownership.
+ * The ASF licenses this file to You under the Apache License, Version 2.0
+ * (the "License"); you may not use this file except in compliance with
+ * the License.  You may obtain a copy of the License at
+ *
+ *      http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.apache.camel.support.jsse;
+
+import java.lang.reflect.Method;
+import java.util.List;
+
+import javax.net.ssl.SSLEngine;
+import javax.net.ssl.SSLParameters;
+
+import org.junit.jupiter.api.Test;
+import org.junit.jupiter.api.condition.EnabledForJreRange;
+import org.junit.jupiter.api.condition.JRE;
+
+import static org.junit.jupiter.api.Assertions.assertEquals;
+
+/**
+ * Blank, duplicate and not trimmed values in the named groups and signature 
schemes lists must not make the configured
+ * list be ignored.
+ */
+public class SSLContextParametersNamedGroupsListTest {
+
+    private static List<String> get(SSLParameters params, String name) throws 
Exception {
+        Method method = SSLParameters.class.getMethod(name);
+        return List.of((String[]) method.invoke(params));
+    }
+
+    @Test
+    @EnabledForJreRange(min = JRE.JAVA_21)
+    public void testNamedGroups() throws Exception {
+        NamedGroupsParameters ngp = new NamedGroupsParameters();
+        ngp.setNamedGroup(List.of("secp384r1", "secp384r1", "", " x25519"));
+        SSLContextParameters scp = new SSLContextParameters();
+        scp.setNamedGroups(ngp);
+
+        SSLEngine engine = scp.createSSLContext(null).createSSLEngine();
+        assertEquals(List.of("secp384r1", "x25519"), 
get(engine.getSSLParameters(), "getNamedGroups"));
+    }
+
+    @Test
+    @EnabledForJreRange(min = JRE.JAVA_21)
+    public void testSignatureSchemes() throws Exception {
+        SignatureSchemesParameters ssp = new SignatureSchemesParameters();
+        ssp.setSignatureScheme(List.of("ecdsa_secp256r1_sha256", " 
ecdsa_secp256r1_sha256", "", "rsa_pss_rsae_sha256"));
+        SSLContextParameters scp = new SSLContextParameters();
+        scp.setSignatureSchemes(ssp);
+
+        SSLEngine engine = scp.createSSLContext(null).createSSLEngine();
+        assertEquals(List.of("ecdsa_secp256r1_sha256", "rsa_pss_rsae_sha256"),
+                get(engine.getSSLParameters(), "getSignatureSchemes"));
+    }
+}

Reply via email to