oscerd opened a new pull request, #27052: URL: https://github.com/apache/camel/pull/27052
## CI Fix **Failed run:** https://github.com/apache/camel/actions/runs/34846241660 (`build (17, false)` of Dependabot's #26411, `bouncycastle-version` 1.85 → 1.86; the JDK 25 job was cancelled with it) This PR carries the same version bump together with the `camel-pqc` changes it needs, so #26411 can be closed once this is merged (Dependabot closes it by itself when `main` is on 1.86). ## Description Bouncy Castle 1.86 removes the legacy post-quantum implementations and parameter-spec classes from the `BCPQC` provider. The CI log shows the first 9 compile errors, because javac stops at the unresolved imports; forcing it past them gives 30 errors in total (24 in 7 main files, 6 in 3 test files), all in `camel-pqc`. None of the other modules using Bouncy Castle imports a class that 1.86 removed. ### Errors Fixed - **`CMCEParameterSpec` / `FrodoParameterSpec` not found.** Classic McEliece and FrodoKEM are now only served by the `BC` provider, which already had them in 1.85. `PQCKeyEncapsulationAlgorithms` maps `CMCE` and `FRODO` to `CMCE` and `FrodoKEM` on `BC`, and the default materials, the tests and `PQCParameterSpecResolver` use `org.bouncycastle.jcajce.spec.CMCEParameterSpec` and `FrodoKEMParameterSpec`. KEM generation/extraction and key encoding round-trip on both 1.85 and 1.86. - **Default parameter sets no longer available.** `KeyAlgorithmSupport` and the AWS Secrets Manager and HashiCorp Vault key lifecycle managers defaulted to `mceliece348864` and `frodokem640aes`, which the `BC` implementation does not have. They now default to `mceliece460896` and `frodokem976aes`. - **`DilithiumParameterSpec`, `SPHINCSPlusParameterSpec`, `KyberParameterSpec` not found.** Since the Bouncy Castle 1.85 adaptation `DILITHIUM`, `SPHINCSPLUS` and `KYBER` generate ML-DSA, SLH-DSA and ML-KEM keys, so `PQCParameterSpecResolver` now resolves them with `MLDSAParameterSpec`, `SLHDSAParameterSpec` and `MLKEMParameterSpec`. This also fixes a latent bug: on 1.85 the legacy Dilithium and SPHINCS+ specs were handed to the ML-DSA and SLH-DSA generators, which reject them (`unknown parameter set name: DILITHIUM3`), so a `DILITHIUM` or `SPHINCSPLUS` endpoint configured with `parameterSpec` could not generate its key. The `kyber512/768/1024` names keep working, as ML-KEM accepts them as aliases. - **`PicnicParameterSpec` not found.** Bouncy Castle 1.86 no longer ships Picnic at all: no provider registers it and no 1.86 jar contains a Picnic class (1.85 had 40). The `PICNIC` signature algorithm, `PQCDefaultPicnicMaterial` and the two Picnic tests are removed; `PQCAlgorithmId.PICNIC` stays as a reserved identifier. ### Breaking changes (documented in the 4.23 upgrade guide) - `PICNIC` is no longer a valid `signatureAlgorithm`, and `PQCSignatureAlgorithms.PICNIC` is gone. - Classic McEliece and FrodoKEM keys generated by the removed `BCPQC` implementations cannot be read by the `BC` provider, which rejects their `1.3.6.1.4.1.22554.5.1.x` / `5.2.x` algorithm identifiers (checked on 1.85 and 1.86), so stored keys have to be regenerated. The same holds for Picnic keys. - `parameterSpec` rejects `mceliece348864*` and `frodokem640*`, and no longer resolves `dilithium2/3/5` for `DILITHIUM` (the ML-DSA names do). ### Deferred Issues - No ticket created. Follow-up outside this repository: `pqc-signature-action.kamelet.yaml` in apache/camel-kamelets still lists `PICNIC` in its `signatureAlgorithm` enum. ## Tests - `PQCParameterSpecResolverTest`: resolves the ML-DSA/SLH-DSA/ML-KEM names for `DILITHIUM`/`SPHINCSPLUS`/`KYBER` and the new Classic McEliece/FrodoKEM names; two parameterized tests check that the resolved spec initializes the `KeyPairGenerator` each algorithm is mapped to, which is the check the `DILITHIUM` and `SPHINCSPLUS` cases fail on 1.85; the dropped `mceliece348864`/`frodokem640aes` sets are rejected. - `camel-pqc` on Bouncy Castle 1.86: the 232 unit tests pass on JDK 21, and on JDK 25 the 232 unit tests (including the JDK 25-only `PQCKeyStoreJdk25KeyConversionTest`) and the 18 integration tests (AWS Secrets Manager and HashiCorp Vault key lifecycle, Testcontainers) pass. - The other modules using `bouncycastle-version` pass on JDK 17 against 1.86: `camel-as2-api` (104), `camel-as2` (13 + 111 ITs), `camel-asn1` (16), `camel-crypto-pgp` (71), `camel-fop` (10), `camel-jsch` (14 + 7 ITs), `camel-pdf` (10), `camel-ssh` (39), `camel-xmlsecurity` (199), `camel-mina-sftp` (26 + 267 ITs) and `camel-ftp` (80 + 372 ITs). The one `camel-ftp` error, `FtpProducerHealthCheckIT`, is locale-dependent and unrelated: it asserts the English `Connection refused` message, fails the same way with Bouncy Castle 1.85 on a non-English locale, and passes with an English one. - The full reactor builds with `mvn clean install -DskipTests`; the only regenerated changes are the catalog copies of the `pqc` metadata and docs. ## Documentation - `pqc-component.adoc`: parameter-set and provider tables updated, Picnic removed. - `pqc-key-lifecycle.adoc`: the examples used the removed `DilithiumParameterSpec`; the default parameter-set table is updated. - Upgrade-guide entry in `camel-4x-upgrade-guide-4_23.adoc`. _Claude Code on behalf of oscerd_ 🤖 Generated with [Claude Code](https://claude.com/claude-code) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
