Claus Ibsen created CAMEL-25107:
-----------------------------------

             Summary: camel-core - SSLContextParameters ignores the configured 
named groups when the list has a duplicate or blank value
                 Key: CAMEL-25107
                 URL: https://issues.apache.org/jira/browse/CAMEL-25107
             Project: Camel
          Issue Type: Bug
          Components: camel-core
            Reporter: Claus Ibsen


When the named groups (or signature schemes) configured on 
{{SSLContextParameters}} contain a duplicate or blank value, the whole 
configured list is silently ignored and the default named groups of the JVM are 
used instead.

The JDK {{SSLParameters.setNamedGroups}} / {{setSignatureSchemes}} reject a 
list with a blank or duplicate value (IllegalArgumentException), and 
BaseSSLContextParameters (which calls them using reflection) ignores the 
exception, so nothing is configured and no error or warning is logged. For 
example {{[secp384r1, secp384r1]}} or {{[secp384r1, ""]}} results in all the 
default groups of the JVM (x25519, secp256r1, ..., ffdhe2048, ...).

This happens easily from camel-main, as {{camel.ssl.namedGroups}} and 
{{camel.ssl.signatureSchemes}} are split on comma without trimming: 
{{secp384r1,,x25519}} (blank) or a copy/paste duplicate ignores the setting, 
and {{secp384r1, x25519}} (space after comma) gives an unknown name " x25519".

On JDK 17 (where the JDK does not have these methods) configured named groups 
and signature schemes are also silently skipped.

The fix trims the values and removes blank and duplicate values (keeping the 
order), fails with a clear error if the JVM still rejects the values, and logs 
a WARN when the JVM does not support configuring them.

_Claude Code on behalf of Claus Ibsen_



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to