Claus Ibsen created CAMEL-25104:
-----------------------------------

             Summary: camel-core - SSLContextParameters should use TLSv1.2 as 
minimum protocol by default
                 Key: CAMEL-25104
                 URL: https://issues.apache.org/jira/browse/CAMEL-25104
             Project: Camel
          Issue Type: Improvement
          Components: camel-core
            Reporter: Claus Ibsen


The default filters of {{SSLContextParameters}} should use TLSv1.2 as the 
minimum protocol:

* The default secure socket protocols filter only excludes {{SSL.*}}, so 
{{TLSv1}} and {{TLSv1.1}} are allowed.
* For an {{SSLServerSocket}} the default filters are applied over all the 
supported protocols and cipher suites (while an {{SSLSocket}} and {{SSLEngine}} 
use the default enabled ones of the JVM), so a server socket created from the 
default SSLContextParameters enables {{TLSv1}} and {{TLSv1.1}} (e.g. 
{{[TLSv1.3, TLSv1.2, TLSv1.1, TLSv1]}} on JDK 21/25), unless they are disabled 
in the JVM security configuration.
* The default cipher suites filter excludes {{.*_DES_.*}} which does not match 
the {{3DES}} cipher suites.

The default protocols filter now excludes {{TLSv1}} and {{TLSv1.1}}, the 
default cipher suites filter excludes {{.*_3DES_.*}}, and the server socket 
uses the default enabled protocols and cipher suites of the JVM as the other 
types do. An older protocol can still be configured explicitly.

_Claude Code on behalf of Claus Ibsen_



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to