[ 
https://issues.apache.org/jira/browse/CAMEL-25106?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Claus Ibsen resolved CAMEL-25106.
---------------------------------
    Resolution: Fixed

Fixed by https://github.com/apache/camel/pull/27010

> camel-kafka - sslContextParameters ignores the SSL endpoint options and does 
> not use the SSL security protocol
> --------------------------------------------------------------------------------------------------------------
>
>                 Key: CAMEL-25106
>                 URL: https://issues.apache.org/jira/browse/CAMEL-25106
>             Project: Camel
>          Issue Type: Bug
>          Components: camel-kafka
>            Reporter: Claus Ibsen
>            Assignee: Claus Ibsen
>            Priority: Major
>             Fix For: 4.23.0
>
>
> camel-kafka with {{sslContextParameters}} (also when using global SSL with 
> {{useGlobalSslContextParameters}}):
> # The SSL endpoint options (such as {{sslTruststoreLocation}}, 
> {{sslTruststorePassword}}, {{sslEndpointAlgorithm}}) are ignored when 
> sslContextParameters is configured, as the configuration uses either the 
> sslContextParameters or the endpoint options (since CAMEL-17615). The 
> documentation of the option says the sslContextParameters are applied before 
> the other SSL endpoint options. For example turning on global SSL on the 
> component replaces the truststore configured on an endpoint.
> # The {{security.protocol}} stays {{PLAINTEXT}} (the default) unless 
> {{securityProtocol}} or {{saslAuthType}} is configured, so the ssl properties 
> are set but SSL is not used.
> The sslContextParameters are now applied before the SSL endpoint options (an 
> endpoint option that is its default value does not replace a value from the 
> sslContextParameters), and the security protocol SSL is used when 
> sslContextParameters is configured and the security protocol is the default.
> _Claude Code on behalf of Claus Ibsen_



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to