This is an automated email from the ASF dual-hosted git repository.

davsclaus pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/camel.git


The following commit(s) were added to refs/heads/main by this push:
     new 6cc0da03324f CAMEL-24999: camel-hivemq - annotate ssl option with 
security=insecure:ssl for the security policy framework (#26891)
6cc0da03324f is described below

commit 6cc0da03324fa69d91e29b51f208ff6d01c08f2e
Author: Andrea Cosentino <[email protected]>
AuthorDate: Tue Sep 29 11:15:18 2026 +0200

    CAMEL-24999: camel-hivemq - annotate ssl option with security=insecure:ssl 
for the security policy framework (#26891)
    
    * CAMEL-24999: camel-hivemq - annotate ssl option with security=insecure:ssl
    * CAMEL-24999: camel-hivemq - document the effect of marking ssl 
insecure:ssl
    
    Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
---
 .../apache/camel/catalog/components/hivemq.json    | 22 +++---
 .../org/apache/camel/component/hivemq/hivemq.json  | 22 +++---
 .../component/hivemq/HiveMQConfiguration.java      |  2 +-
 .../java/org/apache/camel/util/SecurityUtils.java  |  1 +
 .../ROOT/pages/camel-4x-upgrade-guide-4_23.adoc    | 12 +++
 .../dsl/HivemqComponentBuilderFactory.java         | 36 ++++-----
 .../endpoint/dsl/HiveMQEndpointBuilderFactory.java | 90 +++++++++++-----------
 7 files changed, 99 insertions(+), 86 deletions(-)

diff --git 
a/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/components/hivemq.json
 
b/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/components/hivemq.json
index d0cdddb1a0a3..9b0950bfb59f 100644
--- 
a/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/components/hivemq.json
+++ 
b/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/components/hivemq.json
@@ -31,11 +31,11 @@
     "port": { "index": 4, "kind": "property", "displayName": "Port", "group": 
"common", "label": "", "required": false, "type": "integer", "javaType": "int", 
"deprecated": false, "autowired": false, "secret": false, "defaultValue": 1883, 
"configurationClass": "org.apache.camel.component.hivemq.HiveMQConfiguration", 
"configurationField": "configuration", "description": "Port number of the 
HiveMQ MQTT broker." },
     "qos": { "index": 5, "kind": "property", "displayName": "Qos", "group": 
"common", "label": "", "required": false, "type": "enum", "javaType": 
"com.hivemq.client.mqtt.datatypes.MqttQos", "enum": [ "AT_MOST_ONCE", 
"AT_LEAST_ONCE", "EXACTLY_ONCE" ], "deprecated": false, "autowired": false, 
"secret": false, "defaultValue": "AT_LEAST_ONCE", "configurationClass": 
"org.apache.camel.component.hivemq.HiveMQConfiguration", "configurationField": 
"configuration", "description": "Default Quality  [...]
     "retained": { "index": 6, "kind": "property", "displayName": "Retained", 
"group": "common", "label": "", "required": false, "type": "boolean", 
"javaType": "boolean", "deprecated": false, "autowired": false, "secret": 
false, "defaultValue": false, "configurationClass": 
"org.apache.camel.component.hivemq.HiveMQConfiguration", "configurationField": 
"configuration", "description": "Whether published messages should be retained 
by the MQTT broker." },
-    "ssl": { "index": 7, "kind": "property", "displayName": "Ssl", "group": 
"common", "label": "", "required": false, "type": "boolean", "javaType": 
"boolean", "deprecated": false, "autowired": false, "secret": false, 
"defaultValue": false, "configurationClass": 
"org.apache.camel.component.hivemq.HiveMQConfiguration", "configurationField": 
"configuration", "description": "Whether to enable SSL\/TLS encryption for the 
broker connection." },
-    "bridgeErrorHandler": { "index": 8, "kind": "property", "displayName": 
"Bridge Error Handler", "group": "consumer", "label": "consumer", "required": 
false, "type": "boolean", "javaType": "boolean", "deprecated": false, 
"autowired": false, "secret": false, "defaultValue": false, "description": 
"Allows for bridging the consumer to the Camel routing Error Handler, which 
mean any exceptions (if possible) occurred while the Camel consumer is trying 
to pickup incoming messages, or the like [...]
-    "lazyStartProducer": { "index": 9, "kind": "property", "displayName": 
"Lazy Start Producer", "group": "producer", "label": "producer", "required": 
false, "type": "boolean", "javaType": "boolean", "deprecated": false, 
"autowired": false, "secret": false, "defaultValue": false, "description": 
"Whether the producer should be started lazy (on the first message). By 
starting lazy you can use this to allow CamelContext and routes to startup in 
situations where a producer may otherwise fail [...]
-    "autowiredEnabled": { "index": 10, "kind": "property", "displayName": 
"Autowired Enabled", "group": "advanced", "label": "advanced", "required": 
false, "type": "boolean", "javaType": "boolean", "deprecated": false, 
"autowired": false, "secret": false, "defaultValue": true, "description": 
"Whether autowiring is enabled. This is used for automatic autowiring options 
(the option must be marked as autowired) by looking up in the registry to find 
if there is a single instance of matching  [...]
-    "password": { "index": 11, "kind": "property", "displayName": "Password", 
"group": "security", "label": "security", "required": false, "type": "string", 
"javaType": "java.lang.String", "deprecated": false, "deprecationNote": "", 
"autowired": false, "secret": true, "security": "secret", "configurationClass": 
"org.apache.camel.component.hivemq.HiveMQConfiguration", "configurationField": 
"configuration", "description": "Password for authentication with the HiveMQ 
broker." },
+    "bridgeErrorHandler": { "index": 7, "kind": "property", "displayName": 
"Bridge Error Handler", "group": "consumer", "label": "consumer", "required": 
false, "type": "boolean", "javaType": "boolean", "deprecated": false, 
"autowired": false, "secret": false, "defaultValue": false, "description": 
"Allows for bridging the consumer to the Camel routing Error Handler, which 
mean any exceptions (if possible) occurred while the Camel consumer is trying 
to pickup incoming messages, or the like [...]
+    "lazyStartProducer": { "index": 8, "kind": "property", "displayName": 
"Lazy Start Producer", "group": "producer", "label": "producer", "required": 
false, "type": "boolean", "javaType": "boolean", "deprecated": false, 
"autowired": false, "secret": false, "defaultValue": false, "description": 
"Whether the producer should be started lazy (on the first message). By 
starting lazy you can use this to allow CamelContext and routes to startup in 
situations where a producer may otherwise fail [...]
+    "autowiredEnabled": { "index": 9, "kind": "property", "displayName": 
"Autowired Enabled", "group": "advanced", "label": "advanced", "required": 
false, "type": "boolean", "javaType": "boolean", "deprecated": false, 
"autowired": false, "secret": false, "defaultValue": true, "description": 
"Whether autowiring is enabled. This is used for automatic autowiring options 
(the option must be marked as autowired) by looking up in the registry to find 
if there is a single instance of matching t [...]
+    "password": { "index": 10, "kind": "property", "displayName": "Password", 
"group": "security", "label": "security", "required": false, "type": "string", 
"javaType": "java.lang.String", "deprecated": false, "deprecationNote": "", 
"autowired": false, "secret": true, "security": "secret", "configurationClass": 
"org.apache.camel.component.hivemq.HiveMQConfiguration", "configurationField": 
"configuration", "description": "Password for authentication with the HiveMQ 
broker." },
+    "ssl": { "index": 11, "kind": "property", "displayName": "Ssl", "group": 
"security", "label": "security", "required": false, "type": "boolean", 
"javaType": "boolean", "deprecated": false, "autowired": false, "secret": 
false, "security": "insecure:ssl", "insecureValue": "false", "defaultValue": 
false, "configurationClass": 
"org.apache.camel.component.hivemq.HiveMQConfiguration", "configurationField": 
"configuration", "description": "Whether to enable SSL\/TLS encryption for the 
broker [...]
     "username": { "index": 12, "kind": "property", "displayName": "Username", 
"group": "security", "label": "security", "required": false, "type": "string", 
"javaType": "java.lang.String", "deprecated": false, "deprecationNote": "", 
"autowired": false, "secret": false, "configurationClass": 
"org.apache.camel.component.hivemq.HiveMQConfiguration", "configurationField": 
"configuration", "description": "Username for authentication with the HiveMQ 
broker." }
   },
   "headers": {
@@ -52,12 +52,12 @@
     "port": { "index": 4, "kind": "parameter", "displayName": "Port", "group": 
"common", "label": "", "required": false, "type": "integer", "javaType": "int", 
"deprecated": false, "autowired": false, "secret": false, "defaultValue": 1883, 
"configurationClass": "org.apache.camel.component.hivemq.HiveMQConfiguration", 
"configurationField": "configuration", "description": "Port number of the 
HiveMQ MQTT broker." },
     "qos": { "index": 5, "kind": "parameter", "displayName": "Qos", "group": 
"common", "label": "", "required": false, "type": "enum", "javaType": 
"com.hivemq.client.mqtt.datatypes.MqttQos", "enum": [ "AT_MOST_ONCE", 
"AT_LEAST_ONCE", "EXACTLY_ONCE" ], "deprecated": false, "autowired": false, 
"secret": false, "defaultValue": "AT_LEAST_ONCE", "configurationClass": 
"org.apache.camel.component.hivemq.HiveMQConfiguration", "configurationField": 
"configuration", "description": "Default Quality [...]
     "retained": { "index": 6, "kind": "parameter", "displayName": "Retained", 
"group": "common", "label": "", "required": false, "type": "boolean", 
"javaType": "boolean", "deprecated": false, "autowired": false, "secret": 
false, "defaultValue": false, "configurationClass": 
"org.apache.camel.component.hivemq.HiveMQConfiguration", "configurationField": 
"configuration", "description": "Whether published messages should be retained 
by the MQTT broker." },
-    "ssl": { "index": 7, "kind": "parameter", "displayName": "Ssl", "group": 
"common", "label": "", "required": false, "type": "boolean", "javaType": 
"boolean", "deprecated": false, "autowired": false, "secret": false, 
"defaultValue": false, "configurationClass": 
"org.apache.camel.component.hivemq.HiveMQConfiguration", "configurationField": 
"configuration", "description": "Whether to enable SSL\/TLS encryption for the 
broker connection." },
-    "bridgeErrorHandler": { "index": 8, "kind": "parameter", "displayName": 
"Bridge Error Handler", "group": "consumer (advanced)", "label": 
"consumer,advanced", "required": false, "type": "boolean", "javaType": 
"boolean", "deprecated": false, "autowired": false, "secret": false, 
"defaultValue": false, "description": "Allows for bridging the consumer to the 
Camel routing Error Handler, which mean any exceptions (if possible) occurred 
while the Camel consumer is trying to pickup incoming  [...]
-    "exceptionHandler": { "index": 9, "kind": "parameter", "displayName": 
"Exception Handler", "group": "consumer (advanced)", "label": 
"consumer,advanced", "required": false, "type": "object", "javaType": 
"org.apache.camel.spi.ExceptionHandler", "optionalPrefix": "consumer.", 
"deprecated": false, "autowired": false, "secret": false, "description": "To 
let the consumer use a custom ExceptionHandler. Notice if the option 
bridgeErrorHandler is enabled then this option is not in use. By def [...]
-    "exchangePattern": { "index": 10, "kind": "parameter", "displayName": 
"Exchange Pattern", "group": "consumer (advanced)", "label": 
"consumer,advanced", "required": false, "type": "enum", "javaType": 
"org.apache.camel.ExchangePattern", "enum": [ "InOnly", "InOut" ], 
"deprecated": false, "autowired": false, "secret": false, "description": "Sets 
the exchange pattern when the consumer creates an exchange." },
-    "lazyStartProducer": { "index": 11, "kind": "parameter", "displayName": 
"Lazy Start Producer", "group": "producer (advanced)", "label": 
"producer,advanced", "required": false, "type": "boolean", "javaType": 
"boolean", "deprecated": false, "autowired": false, "secret": false, 
"defaultValue": false, "description": "Whether the producer should be started 
lazy (on the first message). By starting lazy you can use this to allow 
CamelContext and routes to startup in situations where a produ [...]
-    "password": { "index": 12, "kind": "parameter", "displayName": "Password", 
"group": "security", "label": "security", "required": false, "type": "string", 
"javaType": "java.lang.String", "deprecated": false, "deprecationNote": "", 
"autowired": false, "secret": true, "security": "secret", "configurationClass": 
"org.apache.camel.component.hivemq.HiveMQConfiguration", "configurationField": 
"configuration", "description": "Password for authentication with the HiveMQ 
broker." },
+    "bridgeErrorHandler": { "index": 7, "kind": "parameter", "displayName": 
"Bridge Error Handler", "group": "consumer (advanced)", "label": 
"consumer,advanced", "required": false, "type": "boolean", "javaType": 
"boolean", "deprecated": false, "autowired": false, "secret": false, 
"defaultValue": false, "description": "Allows for bridging the consumer to the 
Camel routing Error Handler, which mean any exceptions (if possible) occurred 
while the Camel consumer is trying to pickup incoming  [...]
+    "exceptionHandler": { "index": 8, "kind": "parameter", "displayName": 
"Exception Handler", "group": "consumer (advanced)", "label": 
"consumer,advanced", "required": false, "type": "object", "javaType": 
"org.apache.camel.spi.ExceptionHandler", "optionalPrefix": "consumer.", 
"deprecated": false, "autowired": false, "secret": false, "description": "To 
let the consumer use a custom ExceptionHandler. Notice if the option 
bridgeErrorHandler is enabled then this option is not in use. By def [...]
+    "exchangePattern": { "index": 9, "kind": "parameter", "displayName": 
"Exchange Pattern", "group": "consumer (advanced)", "label": 
"consumer,advanced", "required": false, "type": "enum", "javaType": 
"org.apache.camel.ExchangePattern", "enum": [ "InOnly", "InOut" ], 
"deprecated": false, "autowired": false, "secret": false, "description": "Sets 
the exchange pattern when the consumer creates an exchange." },
+    "lazyStartProducer": { "index": 10, "kind": "parameter", "displayName": 
"Lazy Start Producer", "group": "producer (advanced)", "label": 
"producer,advanced", "required": false, "type": "boolean", "javaType": 
"boolean", "deprecated": false, "autowired": false, "secret": false, 
"defaultValue": false, "description": "Whether the producer should be started 
lazy (on the first message). By starting lazy you can use this to allow 
CamelContext and routes to startup in situations where a produ [...]
+    "password": { "index": 11, "kind": "parameter", "displayName": "Password", 
"group": "security", "label": "security", "required": false, "type": "string", 
"javaType": "java.lang.String", "deprecated": false, "deprecationNote": "", 
"autowired": false, "secret": true, "security": "secret", "configurationClass": 
"org.apache.camel.component.hivemq.HiveMQConfiguration", "configurationField": 
"configuration", "description": "Password for authentication with the HiveMQ 
broker." },
+    "ssl": { "index": 12, "kind": "parameter", "displayName": "Ssl", "group": 
"security", "label": "security", "required": false, "type": "boolean", 
"javaType": "boolean", "deprecated": false, "autowired": false, "secret": 
false, "security": "insecure:ssl", "insecureValue": "false", "defaultValue": 
false, "configurationClass": 
"org.apache.camel.component.hivemq.HiveMQConfiguration", "configurationField": 
"configuration", "description": "Whether to enable SSL\/TLS encryption for the 
broke [...]
     "username": { "index": 13, "kind": "parameter", "displayName": "Username", 
"group": "security", "label": "security", "required": false, "type": "string", 
"javaType": "java.lang.String", "deprecated": false, "deprecationNote": "", 
"autowired": false, "secret": false, "configurationClass": 
"org.apache.camel.component.hivemq.HiveMQConfiguration", "configurationField": 
"configuration", "description": "Username for authentication with the HiveMQ 
broker." }
   }
 }
diff --git 
a/components/camel-hivemq/src/generated/resources/META-INF/org/apache/camel/component/hivemq/hivemq.json
 
b/components/camel-hivemq/src/generated/resources/META-INF/org/apache/camel/component/hivemq/hivemq.json
index d0cdddb1a0a3..9b0950bfb59f 100644
--- 
a/components/camel-hivemq/src/generated/resources/META-INF/org/apache/camel/component/hivemq/hivemq.json
+++ 
b/components/camel-hivemq/src/generated/resources/META-INF/org/apache/camel/component/hivemq/hivemq.json
@@ -31,11 +31,11 @@
     "port": { "index": 4, "kind": "property", "displayName": "Port", "group": 
"common", "label": "", "required": false, "type": "integer", "javaType": "int", 
"deprecated": false, "autowired": false, "secret": false, "defaultValue": 1883, 
"configurationClass": "org.apache.camel.component.hivemq.HiveMQConfiguration", 
"configurationField": "configuration", "description": "Port number of the 
HiveMQ MQTT broker." },
     "qos": { "index": 5, "kind": "property", "displayName": "Qos", "group": 
"common", "label": "", "required": false, "type": "enum", "javaType": 
"com.hivemq.client.mqtt.datatypes.MqttQos", "enum": [ "AT_MOST_ONCE", 
"AT_LEAST_ONCE", "EXACTLY_ONCE" ], "deprecated": false, "autowired": false, 
"secret": false, "defaultValue": "AT_LEAST_ONCE", "configurationClass": 
"org.apache.camel.component.hivemq.HiveMQConfiguration", "configurationField": 
"configuration", "description": "Default Quality  [...]
     "retained": { "index": 6, "kind": "property", "displayName": "Retained", 
"group": "common", "label": "", "required": false, "type": "boolean", 
"javaType": "boolean", "deprecated": false, "autowired": false, "secret": 
false, "defaultValue": false, "configurationClass": 
"org.apache.camel.component.hivemq.HiveMQConfiguration", "configurationField": 
"configuration", "description": "Whether published messages should be retained 
by the MQTT broker." },
-    "ssl": { "index": 7, "kind": "property", "displayName": "Ssl", "group": 
"common", "label": "", "required": false, "type": "boolean", "javaType": 
"boolean", "deprecated": false, "autowired": false, "secret": false, 
"defaultValue": false, "configurationClass": 
"org.apache.camel.component.hivemq.HiveMQConfiguration", "configurationField": 
"configuration", "description": "Whether to enable SSL\/TLS encryption for the 
broker connection." },
-    "bridgeErrorHandler": { "index": 8, "kind": "property", "displayName": 
"Bridge Error Handler", "group": "consumer", "label": "consumer", "required": 
false, "type": "boolean", "javaType": "boolean", "deprecated": false, 
"autowired": false, "secret": false, "defaultValue": false, "description": 
"Allows for bridging the consumer to the Camel routing Error Handler, which 
mean any exceptions (if possible) occurred while the Camel consumer is trying 
to pickup incoming messages, or the like [...]
-    "lazyStartProducer": { "index": 9, "kind": "property", "displayName": 
"Lazy Start Producer", "group": "producer", "label": "producer", "required": 
false, "type": "boolean", "javaType": "boolean", "deprecated": false, 
"autowired": false, "secret": false, "defaultValue": false, "description": 
"Whether the producer should be started lazy (on the first message). By 
starting lazy you can use this to allow CamelContext and routes to startup in 
situations where a producer may otherwise fail [...]
-    "autowiredEnabled": { "index": 10, "kind": "property", "displayName": 
"Autowired Enabled", "group": "advanced", "label": "advanced", "required": 
false, "type": "boolean", "javaType": "boolean", "deprecated": false, 
"autowired": false, "secret": false, "defaultValue": true, "description": 
"Whether autowiring is enabled. This is used for automatic autowiring options 
(the option must be marked as autowired) by looking up in the registry to find 
if there is a single instance of matching  [...]
-    "password": { "index": 11, "kind": "property", "displayName": "Password", 
"group": "security", "label": "security", "required": false, "type": "string", 
"javaType": "java.lang.String", "deprecated": false, "deprecationNote": "", 
"autowired": false, "secret": true, "security": "secret", "configurationClass": 
"org.apache.camel.component.hivemq.HiveMQConfiguration", "configurationField": 
"configuration", "description": "Password for authentication with the HiveMQ 
broker." },
+    "bridgeErrorHandler": { "index": 7, "kind": "property", "displayName": 
"Bridge Error Handler", "group": "consumer", "label": "consumer", "required": 
false, "type": "boolean", "javaType": "boolean", "deprecated": false, 
"autowired": false, "secret": false, "defaultValue": false, "description": 
"Allows for bridging the consumer to the Camel routing Error Handler, which 
mean any exceptions (if possible) occurred while the Camel consumer is trying 
to pickup incoming messages, or the like [...]
+    "lazyStartProducer": { "index": 8, "kind": "property", "displayName": 
"Lazy Start Producer", "group": "producer", "label": "producer", "required": 
false, "type": "boolean", "javaType": "boolean", "deprecated": false, 
"autowired": false, "secret": false, "defaultValue": false, "description": 
"Whether the producer should be started lazy (on the first message). By 
starting lazy you can use this to allow CamelContext and routes to startup in 
situations where a producer may otherwise fail [...]
+    "autowiredEnabled": { "index": 9, "kind": "property", "displayName": 
"Autowired Enabled", "group": "advanced", "label": "advanced", "required": 
false, "type": "boolean", "javaType": "boolean", "deprecated": false, 
"autowired": false, "secret": false, "defaultValue": true, "description": 
"Whether autowiring is enabled. This is used for automatic autowiring options 
(the option must be marked as autowired) by looking up in the registry to find 
if there is a single instance of matching t [...]
+    "password": { "index": 10, "kind": "property", "displayName": "Password", 
"group": "security", "label": "security", "required": false, "type": "string", 
"javaType": "java.lang.String", "deprecated": false, "deprecationNote": "", 
"autowired": false, "secret": true, "security": "secret", "configurationClass": 
"org.apache.camel.component.hivemq.HiveMQConfiguration", "configurationField": 
"configuration", "description": "Password for authentication with the HiveMQ 
broker." },
+    "ssl": { "index": 11, "kind": "property", "displayName": "Ssl", "group": 
"security", "label": "security", "required": false, "type": "boolean", 
"javaType": "boolean", "deprecated": false, "autowired": false, "secret": 
false, "security": "insecure:ssl", "insecureValue": "false", "defaultValue": 
false, "configurationClass": 
"org.apache.camel.component.hivemq.HiveMQConfiguration", "configurationField": 
"configuration", "description": "Whether to enable SSL\/TLS encryption for the 
broker [...]
     "username": { "index": 12, "kind": "property", "displayName": "Username", 
"group": "security", "label": "security", "required": false, "type": "string", 
"javaType": "java.lang.String", "deprecated": false, "deprecationNote": "", 
"autowired": false, "secret": false, "configurationClass": 
"org.apache.camel.component.hivemq.HiveMQConfiguration", "configurationField": 
"configuration", "description": "Username for authentication with the HiveMQ 
broker." }
   },
   "headers": {
@@ -52,12 +52,12 @@
     "port": { "index": 4, "kind": "parameter", "displayName": "Port", "group": 
"common", "label": "", "required": false, "type": "integer", "javaType": "int", 
"deprecated": false, "autowired": false, "secret": false, "defaultValue": 1883, 
"configurationClass": "org.apache.camel.component.hivemq.HiveMQConfiguration", 
"configurationField": "configuration", "description": "Port number of the 
HiveMQ MQTT broker." },
     "qos": { "index": 5, "kind": "parameter", "displayName": "Qos", "group": 
"common", "label": "", "required": false, "type": "enum", "javaType": 
"com.hivemq.client.mqtt.datatypes.MqttQos", "enum": [ "AT_MOST_ONCE", 
"AT_LEAST_ONCE", "EXACTLY_ONCE" ], "deprecated": false, "autowired": false, 
"secret": false, "defaultValue": "AT_LEAST_ONCE", "configurationClass": 
"org.apache.camel.component.hivemq.HiveMQConfiguration", "configurationField": 
"configuration", "description": "Default Quality [...]
     "retained": { "index": 6, "kind": "parameter", "displayName": "Retained", 
"group": "common", "label": "", "required": false, "type": "boolean", 
"javaType": "boolean", "deprecated": false, "autowired": false, "secret": 
false, "defaultValue": false, "configurationClass": 
"org.apache.camel.component.hivemq.HiveMQConfiguration", "configurationField": 
"configuration", "description": "Whether published messages should be retained 
by the MQTT broker." },
-    "ssl": { "index": 7, "kind": "parameter", "displayName": "Ssl", "group": 
"common", "label": "", "required": false, "type": "boolean", "javaType": 
"boolean", "deprecated": false, "autowired": false, "secret": false, 
"defaultValue": false, "configurationClass": 
"org.apache.camel.component.hivemq.HiveMQConfiguration", "configurationField": 
"configuration", "description": "Whether to enable SSL\/TLS encryption for the 
broker connection." },
-    "bridgeErrorHandler": { "index": 8, "kind": "parameter", "displayName": 
"Bridge Error Handler", "group": "consumer (advanced)", "label": 
"consumer,advanced", "required": false, "type": "boolean", "javaType": 
"boolean", "deprecated": false, "autowired": false, "secret": false, 
"defaultValue": false, "description": "Allows for bridging the consumer to the 
Camel routing Error Handler, which mean any exceptions (if possible) occurred 
while the Camel consumer is trying to pickup incoming  [...]
-    "exceptionHandler": { "index": 9, "kind": "parameter", "displayName": 
"Exception Handler", "group": "consumer (advanced)", "label": 
"consumer,advanced", "required": false, "type": "object", "javaType": 
"org.apache.camel.spi.ExceptionHandler", "optionalPrefix": "consumer.", 
"deprecated": false, "autowired": false, "secret": false, "description": "To 
let the consumer use a custom ExceptionHandler. Notice if the option 
bridgeErrorHandler is enabled then this option is not in use. By def [...]
-    "exchangePattern": { "index": 10, "kind": "parameter", "displayName": 
"Exchange Pattern", "group": "consumer (advanced)", "label": 
"consumer,advanced", "required": false, "type": "enum", "javaType": 
"org.apache.camel.ExchangePattern", "enum": [ "InOnly", "InOut" ], 
"deprecated": false, "autowired": false, "secret": false, "description": "Sets 
the exchange pattern when the consumer creates an exchange." },
-    "lazyStartProducer": { "index": 11, "kind": "parameter", "displayName": 
"Lazy Start Producer", "group": "producer (advanced)", "label": 
"producer,advanced", "required": false, "type": "boolean", "javaType": 
"boolean", "deprecated": false, "autowired": false, "secret": false, 
"defaultValue": false, "description": "Whether the producer should be started 
lazy (on the first message). By starting lazy you can use this to allow 
CamelContext and routes to startup in situations where a produ [...]
-    "password": { "index": 12, "kind": "parameter", "displayName": "Password", 
"group": "security", "label": "security", "required": false, "type": "string", 
"javaType": "java.lang.String", "deprecated": false, "deprecationNote": "", 
"autowired": false, "secret": true, "security": "secret", "configurationClass": 
"org.apache.camel.component.hivemq.HiveMQConfiguration", "configurationField": 
"configuration", "description": "Password for authentication with the HiveMQ 
broker." },
+    "bridgeErrorHandler": { "index": 7, "kind": "parameter", "displayName": 
"Bridge Error Handler", "group": "consumer (advanced)", "label": 
"consumer,advanced", "required": false, "type": "boolean", "javaType": 
"boolean", "deprecated": false, "autowired": false, "secret": false, 
"defaultValue": false, "description": "Allows for bridging the consumer to the 
Camel routing Error Handler, which mean any exceptions (if possible) occurred 
while the Camel consumer is trying to pickup incoming  [...]
+    "exceptionHandler": { "index": 8, "kind": "parameter", "displayName": 
"Exception Handler", "group": "consumer (advanced)", "label": 
"consumer,advanced", "required": false, "type": "object", "javaType": 
"org.apache.camel.spi.ExceptionHandler", "optionalPrefix": "consumer.", 
"deprecated": false, "autowired": false, "secret": false, "description": "To 
let the consumer use a custom ExceptionHandler. Notice if the option 
bridgeErrorHandler is enabled then this option is not in use. By def [...]
+    "exchangePattern": { "index": 9, "kind": "parameter", "displayName": 
"Exchange Pattern", "group": "consumer (advanced)", "label": 
"consumer,advanced", "required": false, "type": "enum", "javaType": 
"org.apache.camel.ExchangePattern", "enum": [ "InOnly", "InOut" ], 
"deprecated": false, "autowired": false, "secret": false, "description": "Sets 
the exchange pattern when the consumer creates an exchange." },
+    "lazyStartProducer": { "index": 10, "kind": "parameter", "displayName": 
"Lazy Start Producer", "group": "producer (advanced)", "label": 
"producer,advanced", "required": false, "type": "boolean", "javaType": 
"boolean", "deprecated": false, "autowired": false, "secret": false, 
"defaultValue": false, "description": "Whether the producer should be started 
lazy (on the first message). By starting lazy you can use this to allow 
CamelContext and routes to startup in situations where a produ [...]
+    "password": { "index": 11, "kind": "parameter", "displayName": "Password", 
"group": "security", "label": "security", "required": false, "type": "string", 
"javaType": "java.lang.String", "deprecated": false, "deprecationNote": "", 
"autowired": false, "secret": true, "security": "secret", "configurationClass": 
"org.apache.camel.component.hivemq.HiveMQConfiguration", "configurationField": 
"configuration", "description": "Password for authentication with the HiveMQ 
broker." },
+    "ssl": { "index": 12, "kind": "parameter", "displayName": "Ssl", "group": 
"security", "label": "security", "required": false, "type": "boolean", 
"javaType": "boolean", "deprecated": false, "autowired": false, "secret": 
false, "security": "insecure:ssl", "insecureValue": "false", "defaultValue": 
false, "configurationClass": 
"org.apache.camel.component.hivemq.HiveMQConfiguration", "configurationField": 
"configuration", "description": "Whether to enable SSL\/TLS encryption for the 
broke [...]
     "username": { "index": 13, "kind": "parameter", "displayName": "Username", 
"group": "security", "label": "security", "required": false, "type": "string", 
"javaType": "java.lang.String", "deprecated": false, "deprecationNote": "", 
"autowired": false, "secret": false, "configurationClass": 
"org.apache.camel.component.hivemq.HiveMQConfiguration", "configurationField": 
"configuration", "description": "Username for authentication with the HiveMQ 
broker." }
   }
 }
diff --git 
a/components/camel-hivemq/src/main/java/org/apache/camel/component/hivemq/HiveMQConfiguration.java
 
b/components/camel-hivemq/src/main/java/org/apache/camel/component/hivemq/HiveMQConfiguration.java
index aead89a0fde6..47bd662534e4 100644
--- 
a/components/camel-hivemq/src/main/java/org/apache/camel/component/hivemq/HiveMQConfiguration.java
+++ 
b/components/camel-hivemq/src/main/java/org/apache/camel/component/hivemq/HiveMQConfiguration.java
@@ -78,7 +78,7 @@ public class HiveMQConfiguration implements Cloneable {
     /**
      * Whether to enable SSL/TLS encryption for the broker connection.
      */
-    @UriParam(defaultValue = "false")
+    @UriParam(defaultValue = "false", label = "security", security = 
"insecure:ssl", insecureValue = "false")
     private boolean ssl;
 
     public String getHost() {
diff --git 
a/core/camel-util/src/main/java/org/apache/camel/util/SecurityUtils.java 
b/core/camel-util/src/main/java/org/apache/camel/util/SecurityUtils.java
index 8cdcd2972e95..ed7178491d1b 100644
--- a/core/camel-util/src/main/java/org/apache/camel/util/SecurityUtils.java
+++ b/core/camel-util/src/main/java/org/apache/camel/util/SecurityUtils.java
@@ -84,6 +84,7 @@ public final class SecurityUtils {
         map.put("sendenabled", new SecurityOption(INSECURE_DEV, "true"));
         map.put("serializablepackages", new 
SecurityOption(INSECURE_SERIALIZATION, ""));
         map.put("skiptlsverify", new SecurityOption(INSECURE_SSL, "true"));
+        map.put("ssl", new SecurityOption(INSECURE_SSL, VALUE_FALSE));
         map.put("sslendpointalgorithm", new SecurityOption(INSECURE_SSL, 
"none"));
         map.put("stricthostkeychecking", new SecurityOption(INSECURE_SSL, ""));
         map.put("tls", new SecurityOption(INSECURE_SSL, VALUE_FALSE));
diff --git 
a/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_23.adoc 
b/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_23.adoc
index c62c31eddd11..04d6027f2ded 100644
--- a/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_23.adoc
+++ b/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_23.adoc
@@ -1230,6 +1230,18 @@ component publishes events in the CloudEvents schema, 
which has no `dataVersion`
 belongs to the legacy Event Grid event schema), so the header was read but 
never applied to the
 published event. Remove any use of that header; there is no CloudEvents 
equivalent.
 
+=== camel-hivemq
+
+The `ssl` option is now marked `insecure:ssl`, so setting it to `false` in the 
configuration is reported
+by the xref:security-policy.adoc[security policy] check: a warning by default, 
and a startup failure with
+the `prod` profile or `camel.security.insecureSslPolicy = fail`.
+
+The check matches a configuration property by its option name, not by its 
component. It therefore also
+applies when `ssl=false` is set on the other components that have an `ssl` 
option: `camel-clickhouse`,
+`camel-netty`, `camel-netty-http` and `camel-oaipmh`, for example 
`camel.component.netty.ssl = false` in
+`application.properties`. The `tls` option of `camel-pinecone` already worked 
this way for `tls=false`. To
+keep such a setting under a `fail` policy, list it in 
`camel.security.allowedProperties`.
+
 === camel-hazelcast
 
 `ReplicatedHazelcastAggregationRepository` now applies the same default
diff --git 
a/dsl/camel-componentdsl/src/generated/java/org/apache/camel/builder/component/dsl/HivemqComponentBuilderFactory.java
 
b/dsl/camel-componentdsl/src/generated/java/org/apache/camel/builder/component/dsl/HivemqComponentBuilderFactory.java
index 8259ec7da490..01a5ac2a0b7e 100644
--- 
a/dsl/camel-componentdsl/src/generated/java/org/apache/camel/builder/component/dsl/HivemqComponentBuilderFactory.java
+++ 
b/dsl/camel-componentdsl/src/generated/java/org/apache/camel/builder/component/dsl/HivemqComponentBuilderFactory.java
@@ -170,23 +170,6 @@ public interface HivemqComponentBuilderFactory {
         }
     
         
-        /**
-         * Whether to enable SSL/TLS encryption for the broker connection.
-         * 
-         * The option is a: &lt;code&gt;boolean&lt;/code&gt; type.
-         * 
-         * Default: false
-         * Group: common
-         * 
-         * @param ssl the value to set
-         * @return the dsl builder
-         */
-        default HivemqComponentBuilder ssl(boolean ssl) {
-            doSetProperty("ssl", ssl);
-            return this;
-        }
-    
-        
         /**
          * Allows for bridging the consumer to the Camel routing Error Handler,
          * which mean any exceptions (if possible) occurred while the Camel
@@ -276,6 +259,23 @@ public interface HivemqComponentBuilderFactory {
             return this;
         }
     
+        
+        /**
+         * Whether to enable SSL/TLS encryption for the broker connection.
+         * 
+         * The option is a: &lt;code&gt;boolean&lt;/code&gt; type.
+         * 
+         * Default: false
+         * Group: security
+         * 
+         * @param ssl the value to set
+         * @return the dsl builder
+         */
+        default HivemqComponentBuilder ssl(boolean ssl) {
+            doSetProperty("ssl", ssl);
+            return this;
+        }
+    
         /**
          * Username for authentication with the HiveMQ broker.
          * 
@@ -318,11 +318,11 @@ public interface HivemqComponentBuilderFactory {
             case "port": getOrCreateConfiguration((HiveMQComponent) 
component).setPort((int) value); return true;
             case "qos": getOrCreateConfiguration((HiveMQComponent) 
component).setQos((com.hivemq.client.mqtt.datatypes.MqttQos) value); return 
true;
             case "retained": getOrCreateConfiguration((HiveMQComponent) 
component).setRetained((boolean) value); return true;
-            case "ssl": getOrCreateConfiguration((HiveMQComponent) 
component).setSsl((boolean) value); return true;
             case "bridgeErrorHandler": ((HiveMQComponent) 
component).setBridgeErrorHandler((boolean) value); return true;
             case "lazyStartProducer": ((HiveMQComponent) 
component).setLazyStartProducer((boolean) value); return true;
             case "autowiredEnabled": ((HiveMQComponent) 
component).setAutowiredEnabled((boolean) value); return true;
             case "password": getOrCreateConfiguration((HiveMQComponent) 
component).setPassword((java.lang.String) value); return true;
+            case "ssl": getOrCreateConfiguration((HiveMQComponent) 
component).setSsl((boolean) value); return true;
             case "username": getOrCreateConfiguration((HiveMQComponent) 
component).setUsername((java.lang.String) value); return true;
             default: return false;
             }
diff --git 
a/dsl/camel-endpointdsl/src/generated/java/org/apache/camel/builder/endpoint/dsl/HiveMQEndpointBuilderFactory.java
 
b/dsl/camel-endpointdsl/src/generated/java/org/apache/camel/builder/endpoint/dsl/HiveMQEndpointBuilderFactory.java
index ab433976f180..80a520c3918c 100644
--- 
a/dsl/camel-endpointdsl/src/generated/java/org/apache/camel/builder/endpoint/dsl/HiveMQEndpointBuilderFactory.java
+++ 
b/dsl/camel-endpointdsl/src/generated/java/org/apache/camel/builder/endpoint/dsl/HiveMQEndpointBuilderFactory.java
@@ -197,47 +197,47 @@ public interface HiveMQEndpointBuilderFactory {
             return this;
         }
         /**
-         * Whether to enable SSL/TLS encryption for the broker connection.
+         * Password for authentication with the HiveMQ broker.
          * 
-         * The option is a: <code>boolean</code> type.
+         * The option is a: <code>java.lang.String</code> type.
          * 
-         * Default: false
-         * Group: common
+         * Group: security
          * 
-         * @param ssl the value to set
+         * @param password the value to set
          * @return the dsl builder
          */
-        default HiveMQEndpointConsumerBuilder ssl(boolean ssl) {
-            doSetProperty("ssl", ssl);
+        default HiveMQEndpointConsumerBuilder password(String password) {
+            doSetProperty("password", password);
             return this;
         }
         /**
          * Whether to enable SSL/TLS encryption for the broker connection.
          * 
-         * The option will be converted to a <code>boolean</code> type.
+         * The option is a: <code>boolean</code> type.
          * 
          * Default: false
-         * Group: common
+         * Group: security
          * 
          * @param ssl the value to set
          * @return the dsl builder
          */
-        default HiveMQEndpointConsumerBuilder ssl(String ssl) {
+        default HiveMQEndpointConsumerBuilder ssl(boolean ssl) {
             doSetProperty("ssl", ssl);
             return this;
         }
         /**
-         * Password for authentication with the HiveMQ broker.
+         * Whether to enable SSL/TLS encryption for the broker connection.
          * 
-         * The option is a: <code>java.lang.String</code> type.
+         * The option will be converted to a <code>boolean</code> type.
          * 
+         * Default: false
          * Group: security
          * 
-         * @param password the value to set
+         * @param ssl the value to set
          * @return the dsl builder
          */
-        default HiveMQEndpointConsumerBuilder password(String password) {
-            doSetProperty("password", password);
+        default HiveMQEndpointConsumerBuilder ssl(String ssl) {
+            doSetProperty("ssl", ssl);
             return this;
         }
         /**
@@ -548,47 +548,47 @@ public interface HiveMQEndpointBuilderFactory {
             return this;
         }
         /**
-         * Whether to enable SSL/TLS encryption for the broker connection.
+         * Password for authentication with the HiveMQ broker.
          * 
-         * The option is a: <code>boolean</code> type.
+         * The option is a: <code>java.lang.String</code> type.
          * 
-         * Default: false
-         * Group: common
+         * Group: security
          * 
-         * @param ssl the value to set
+         * @param password the value to set
          * @return the dsl builder
          */
-        default HiveMQEndpointProducerBuilder ssl(boolean ssl) {
-            doSetProperty("ssl", ssl);
+        default HiveMQEndpointProducerBuilder password(String password) {
+            doSetProperty("password", password);
             return this;
         }
         /**
          * Whether to enable SSL/TLS encryption for the broker connection.
          * 
-         * The option will be converted to a <code>boolean</code> type.
+         * The option is a: <code>boolean</code> type.
          * 
          * Default: false
-         * Group: common
+         * Group: security
          * 
          * @param ssl the value to set
          * @return the dsl builder
          */
-        default HiveMQEndpointProducerBuilder ssl(String ssl) {
+        default HiveMQEndpointProducerBuilder ssl(boolean ssl) {
             doSetProperty("ssl", ssl);
             return this;
         }
         /**
-         * Password for authentication with the HiveMQ broker.
+         * Whether to enable SSL/TLS encryption for the broker connection.
          * 
-         * The option is a: <code>java.lang.String</code> type.
+         * The option will be converted to a <code>boolean</code> type.
          * 
+         * Default: false
          * Group: security
          * 
-         * @param password the value to set
+         * @param ssl the value to set
          * @return the dsl builder
          */
-        default HiveMQEndpointProducerBuilder password(String password) {
-            doSetProperty("password", password);
+        default HiveMQEndpointProducerBuilder ssl(String ssl) {
+            doSetProperty("ssl", ssl);
             return this;
         }
         /**
@@ -828,47 +828,47 @@ public interface HiveMQEndpointBuilderFactory {
             return this;
         }
         /**
-         * Whether to enable SSL/TLS encryption for the broker connection.
+         * Password for authentication with the HiveMQ broker.
          * 
-         * The option is a: <code>boolean</code> type.
+         * The option is a: <code>java.lang.String</code> type.
          * 
-         * Default: false
-         * Group: common
+         * Group: security
          * 
-         * @param ssl the value to set
+         * @param password the value to set
          * @return the dsl builder
          */
-        default HiveMQEndpointBuilder ssl(boolean ssl) {
-            doSetProperty("ssl", ssl);
+        default HiveMQEndpointBuilder password(String password) {
+            doSetProperty("password", password);
             return this;
         }
         /**
          * Whether to enable SSL/TLS encryption for the broker connection.
          * 
-         * The option will be converted to a <code>boolean</code> type.
+         * The option is a: <code>boolean</code> type.
          * 
          * Default: false
-         * Group: common
+         * Group: security
          * 
          * @param ssl the value to set
          * @return the dsl builder
          */
-        default HiveMQEndpointBuilder ssl(String ssl) {
+        default HiveMQEndpointBuilder ssl(boolean ssl) {
             doSetProperty("ssl", ssl);
             return this;
         }
         /**
-         * Password for authentication with the HiveMQ broker.
+         * Whether to enable SSL/TLS encryption for the broker connection.
          * 
-         * The option is a: <code>java.lang.String</code> type.
+         * The option will be converted to a <code>boolean</code> type.
          * 
+         * Default: false
          * Group: security
          * 
-         * @param password the value to set
+         * @param ssl the value to set
          * @return the dsl builder
          */
-        default HiveMQEndpointBuilder password(String password) {
-            doSetProperty("password", password);
+        default HiveMQEndpointBuilder ssl(String ssl) {
+            doSetProperty("ssl", ssl);
             return this;
         }
         /**

Reply via email to