Claus Ibsen created CAMEL-25104:
-----------------------------------
Summary: camel-core - SSLContextParameters should use TLSv1.2 as
minimum protocol by default
Key: CAMEL-25104
URL: https://issues.apache.org/jira/browse/CAMEL-25104
Project: Camel
Issue Type: Improvement
Components: camel-core
Reporter: Claus Ibsen
The default filters of {{SSLContextParameters}} should use TLSv1.2 as the
minimum protocol:
* The default secure socket protocols filter only excludes {{SSL.*}}, so
{{TLSv1}} and {{TLSv1.1}} are allowed.
* For an {{SSLServerSocket}} the default filters are applied over all the
supported protocols and cipher suites (while an {{SSLSocket}} and {{SSLEngine}}
use the default enabled ones of the JVM), so a server socket created from the
default SSLContextParameters enables {{TLSv1}} and {{TLSv1.1}} (e.g.
{{[TLSv1.3, TLSv1.2, TLSv1.1, TLSv1]}} on JDK 21/25), unless they are disabled
in the JVM security configuration.
* The default cipher suites filter excludes {{.*_DES_.*}} which does not match
the {{3DES}} cipher suites.
The default protocols filter now excludes {{TLSv1}} and {{TLSv1.1}}, the
default cipher suites filter excludes {{.*_3DES_.*}}, and the server socket
uses the default enabled protocols and cipher suites of the JVM as the other
types do. An older protocol can still be configured explicitly.
_Claude Code on behalf of Claus Ibsen_
--
This message was sent by Atlassian Jira
(v8.20.10#820010)