[
https://issues.apache.org/jira/browse/CAMEL-25104?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Claus Ibsen resolved CAMEL-25104.
---------------------------------
Resolution: Fixed
Fixed by https://github.com/apache/camel/pull/27008
> camel-core - SSLContextParameters should use TLSv1.2 as minimum protocol by
> default
> -----------------------------------------------------------------------------------
>
> Key: CAMEL-25104
> URL: https://issues.apache.org/jira/browse/CAMEL-25104
> Project: Camel
> Issue Type: Improvement
> Components: camel-core
> Reporter: Claus Ibsen
> Assignee: Claus Ibsen
> Priority: Major
> Fix For: 4.23.0
>
>
> The default filters of {{SSLContextParameters}} should use TLSv1.2 as the
> minimum protocol:
> * The default secure socket protocols filter only excludes {{SSL.*}}, so
> {{TLSv1}} and {{TLSv1.1}} are allowed.
> * For an {{SSLServerSocket}} the default filters are applied over all the
> supported protocols and cipher suites (while an {{SSLSocket}} and
> {{SSLEngine}} use the default enabled ones of the JVM), so a server socket
> created from the default SSLContextParameters enables {{TLSv1}} and
> {{TLSv1.1}} (e.g. {{[TLSv1.3, TLSv1.2, TLSv1.1, TLSv1]}} on JDK 21/25),
> unless they are disabled in the JVM security configuration.
> * The default cipher suites filter excludes {{.*_DES_.*}} which does not
> match the {{3DES}} cipher suites.
> The default protocols filter now excludes {{TLSv1}} and {{TLSv1.1}}, the
> default cipher suites filter excludes {{.*_3DES_.*}}, and the server socket
> uses the default enabled protocols and cipher suites of the JVM as the other
> types do. An older protocol can still be configured explicitly.
> _Claude Code on behalf of Claus Ibsen_
--
This message was sent by Atlassian Jira
(v8.20.10#820010)