[
https://issues.apache.org/jira/browse/CAMEL-25107?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Claus Ibsen updated CAMEL-25107:
--------------------------------
Fix Version/s: 4.23.0
> camel-core - SSLContextParameters ignores the configured named groups when
> the list has a duplicate or blank value
> ------------------------------------------------------------------------------------------------------------------
>
> Key: CAMEL-25107
> URL: https://issues.apache.org/jira/browse/CAMEL-25107
> Project: Camel
> Issue Type: Bug
> Components: camel-core
> Reporter: Claus Ibsen
> Assignee: Claus Ibsen
> Priority: Major
> Fix For: 4.23.0
>
>
> When the named groups (or signature schemes) configured on
> {{SSLContextParameters}} contain a duplicate or blank value, the whole
> configured list is silently ignored and the default named groups of the JVM
> are used instead.
> The JDK {{SSLParameters.setNamedGroups}} / {{setSignatureSchemes}} reject a
> list with a blank or duplicate value (IllegalArgumentException), and
> BaseSSLContextParameters (which calls them using reflection) ignores the
> exception, so nothing is configured and no error or warning is logged. For
> example {{[secp384r1, secp384r1]}} or {{[secp384r1, ""]}} results in all the
> default groups of the JVM (x25519, secp256r1, ..., ffdhe2048, ...).
> This happens easily from camel-main, as {{camel.ssl.namedGroups}} and
> {{camel.ssl.signatureSchemes}} are split on comma without trimming:
> {{secp384r1,,x25519}} (blank) or a copy/paste duplicate ignores the setting,
> and {{secp384r1, x25519}} (space after comma) gives an unknown name " x25519".
> On JDK 17 (where the JDK does not have these methods) configured named groups
> and signature schemes are also silently skipped.
> The fix trims the values and removes blank and duplicate values (keeping the
> order), fails with a clear error if the JVM still rejects the values, and
> logs a WARN when the JVM does not support configuring them.
> _Claude Code on behalf of Claus Ibsen_
--
This message was sent by Atlassian Jira
(v8.20.10#820010)