This is an automated email from the ASF dual-hosted git repository.
gnodet pushed a commit to branch camel-4.22.x
in repository https://gitbox.apache.org/repos/asf/camel.git
The following commit(s) were added to refs/heads/camel-4.22.x by this push:
new 452807d00ce1 [backport camel-4.22.x] CAMEL-25107: camel-core -
SSLContextParameters ignores the configured named groups when the list has a
duplicate or blank value (#27028)
452807d00ce1 is described below
commit 452807d00ce1579739881fcec0bef26a69b508e1
Author: Guillaume Nodet <[email protected]>
AuthorDate: Tue Sep 29 01:06:40 2026 +0200
[backport camel-4.22.x] CAMEL-25107: camel-core - SSLContextParameters
ignores the configured named groups when the list has a duplicate or blank
value (#27028)
---
.../support/jsse/BaseSSLContextParameters.java | 54 ++++++++++++++----
.../SSLContextParametersNamedGroupsListTest.java | 66 ++++++++++++++++++++++
2 files changed, 110 insertions(+), 10 deletions(-)
diff --git
a/core/camel-api/src/main/java/org/apache/camel/support/jsse/BaseSSLContextParameters.java
b/core/camel-api/src/main/java/org/apache/camel/support/jsse/BaseSSLContextParameters.java
index 2d3e0a5ad909..689903e1c0a3 100644
---
a/core/camel-api/src/main/java/org/apache/camel/support/jsse/BaseSSLContextParameters.java
+++
b/core/camel-api/src/main/java/org/apache/camel/support/jsse/BaseSSLContextParameters.java
@@ -17,6 +17,7 @@
package org.apache.camel.support.jsse;
import java.io.IOException;
+import java.lang.reflect.InvocationTargetException;
import java.lang.reflect.Method;
import java.net.InetAddress;
import java.net.ServerSocket;
@@ -28,9 +29,11 @@ import java.util.ArrayList;
import java.util.Arrays;
import java.util.Collection;
import java.util.Collections;
+import java.util.LinkedHashSet;
import java.util.LinkedList;
import java.util.List;
import java.util.Objects;
+import java.util.Set;
import java.util.regex.Matcher;
import java.util.regex.Pattern;
@@ -99,6 +102,9 @@ public abstract class BaseSSLContextParameters extends
JsseParameters {
private static final String SSL_SERVER_SOCKET_SIGNATURE_SCHEME_LOG_MSG
= createSignatureSchemeLogMessage("SSLServerSocket");
+ private static volatile boolean namedGroupsNotSupportedWarned;
+ private static volatile boolean signatureSchemesNotSupportedWarned;
+
// Reflection handles for JDK 19/20 SSLParameters methods (not available
on JDK 17)
private static final @Nullable Method GET_NAMED_GROUPS;
private static final @Nullable Method SET_NAMED_GROUPS;
@@ -134,15 +140,42 @@ public abstract class BaseSSLContextParameters extends
JsseParameters {
private static void setNamedGroupsOnParams(SSLParameters params, String[]
namedGroups) {
if (SET_NAMED_GROUPS == null) {
+ if (!namedGroupsNotSupportedWarned) {
+ namedGroupsNotSupportedWarned = true;
+ LOG.warn("The named groups cannot be configured as this JVM
does not support it (requires JDK 20 or newer)");
+ }
return;
}
+ invokeSetter(SET_NAMED_GROUPS, params, namedGroups, "named groups");
+ }
+
+ private static void invokeSetter(Method method, SSLParameters params,
String[] values, String name) {
try {
- SET_NAMED_GROUPS.invoke(params, (Object) namedGroups);
- } catch (Exception e) {
- // ignore
+ method.invoke(params, (Object) values);
+ } catch (InvocationTargetException e) {
+ // the configured values must not be silently ignored (the JVM
defaults would be used instead)
+ Throwable cause = e.getCause() != null ? e.getCause() : e;
+ throw new IllegalArgumentException(
+ "Cannot configure the " + name + " " +
Arrays.toString(values) + " due to: " + cause.getMessage(), cause);
+ } catch (IllegalAccessException e) {
+ throw new IllegalStateException(e);
}
}
+ /**
+ * Trims the values, and removes blank and duplicate values (keeping the
order), as the JVM does not allow blank or
+ * duplicate named groups and signature schemes.
+ */
+ static List<String> normalizeValues(List<String> values) {
+ Set<String> answer = new LinkedHashSet<>();
+ for (String value : values) {
+ if (value != null && !value.isBlank()) {
+ answer.add(value.trim());
+ }
+ }
+ return new ArrayList<>(answer);
+ }
+
private static String @Nullable []
getSignatureSchemesFromParams(SSLParameters params) {
if (GET_SIGNATURE_SCHEMES == null) {
return null;
@@ -156,13 +189,14 @@ public abstract class BaseSSLContextParameters extends
JsseParameters {
private static void setSignatureSchemesOnParams(SSLParameters params,
String[] signatureSchemes) {
if (SET_SIGNATURE_SCHEMES == null) {
+ if (!signatureSchemesNotSupportedWarned) {
+ signatureSchemesNotSupportedWarned = true;
+ LOG.warn(
+ "The signature schemes cannot be configured as this
JVM does not support it (requires JDK 19 or newer)");
+ }
return;
}
- try {
- SET_SIGNATURE_SCHEMES.invoke(params, (Object) signatureSchemes);
- } catch (Exception e) {
- // ignore
- }
+ invokeSetter(SET_SIGNATURE_SCHEMES, params, signatureSchemes,
"signature schemes");
}
/**
@@ -1190,7 +1224,7 @@ public abstract class BaseSSLContextParameters extends
JsseParameters {
Collection<String> filteredNamedGroups;
if (enabledNamedGroups != null) {
- filteredNamedGroups = new ArrayList<>(enabledNamedGroups);
+ filteredNamedGroups = normalizeValues(enabledNamedGroups);
} else if (enabledNamedGroupsPatterns != null) {
filteredNamedGroups = this.filter(
null, Arrays.asList(currentNamedGroups),
@@ -1227,7 +1261,7 @@ public abstract class BaseSSLContextParameters extends
JsseParameters {
Collection<String> filteredSignatureSchemes;
if (enabledSignatureSchemes != null) {
- filteredSignatureSchemes = new
ArrayList<>(enabledSignatureSchemes);
+ filteredSignatureSchemes =
normalizeValues(enabledSignatureSchemes);
} else if (enabledSignatureSchemesPatterns != null) {
filteredSignatureSchemes = this.filter(
null, Arrays.asList(currentSignatureSchemes),
diff --git
a/core/camel-core/src/test/java/org/apache/camel/support/jsse/SSLContextParametersNamedGroupsListTest.java
b/core/camel-core/src/test/java/org/apache/camel/support/jsse/SSLContextParametersNamedGroupsListTest.java
new file mode 100644
index 000000000000..d5a67af1f8ed
--- /dev/null
+++
b/core/camel-core/src/test/java/org/apache/camel/support/jsse/SSLContextParametersNamedGroupsListTest.java
@@ -0,0 +1,66 @@
+/*
+ * Licensed to the Apache Software Foundation (ASF) under one or more
+ * contributor license agreements. See the NOTICE file distributed with
+ * this work for additional information regarding copyright ownership.
+ * The ASF licenses this file to You under the Apache License, Version 2.0
+ * (the "License"); you may not use this file except in compliance with
+ * the License. You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.apache.camel.support.jsse;
+
+import java.lang.reflect.Method;
+import java.util.List;
+
+import javax.net.ssl.SSLEngine;
+import javax.net.ssl.SSLParameters;
+
+import org.junit.jupiter.api.Test;
+import org.junit.jupiter.api.condition.EnabledForJreRange;
+import org.junit.jupiter.api.condition.JRE;
+
+import static org.junit.jupiter.api.Assertions.assertEquals;
+
+/**
+ * Blank, duplicate and not trimmed values in the named groups and signature
schemes lists must not make the configured
+ * list be ignored.
+ */
+public class SSLContextParametersNamedGroupsListTest {
+
+ private static List<String> get(SSLParameters params, String name) throws
Exception {
+ Method method = SSLParameters.class.getMethod(name);
+ return List.of((String[]) method.invoke(params));
+ }
+
+ @Test
+ @EnabledForJreRange(min = JRE.JAVA_21)
+ public void testNamedGroups() throws Exception {
+ NamedGroupsParameters ngp = new NamedGroupsParameters();
+ ngp.setNamedGroup(List.of("secp384r1", "secp384r1", "", " x25519"));
+ SSLContextParameters scp = new SSLContextParameters();
+ scp.setNamedGroups(ngp);
+
+ SSLEngine engine = scp.createSSLContext(null).createSSLEngine();
+ assertEquals(List.of("secp384r1", "x25519"),
get(engine.getSSLParameters(), "getNamedGroups"));
+ }
+
+ @Test
+ @EnabledForJreRange(min = JRE.JAVA_21)
+ public void testSignatureSchemes() throws Exception {
+ SignatureSchemesParameters ssp = new SignatureSchemesParameters();
+ ssp.setSignatureScheme(List.of("ecdsa_secp256r1_sha256", "
ecdsa_secp256r1_sha256", "", "rsa_pss_rsae_sha256"));
+ SSLContextParameters scp = new SSLContextParameters();
+ scp.setSignatureSchemes(ssp);
+
+ SSLEngine engine = scp.createSSLContext(null).createSSLEngine();
+ assertEquals(List.of("ecdsa_secp256r1_sha256", "rsa_pss_rsae_sha256"),
+ get(engine.getSSLParameters(), "getSignatureSchemes"));
+ }
+}