[ 
https://issues.apache.org/jira/browse/CAMEL-25107?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Claus Ibsen updated CAMEL-25107:
--------------------------------
    Fix Version/s: 4.23.0

> camel-core - SSLContextParameters ignores the configured named groups when 
> the list has a duplicate or blank value
> ------------------------------------------------------------------------------------------------------------------
>
>                 Key: CAMEL-25107
>                 URL: https://issues.apache.org/jira/browse/CAMEL-25107
>             Project: Camel
>          Issue Type: Bug
>          Components: camel-core
>            Reporter: Claus Ibsen
>            Assignee: Claus Ibsen
>            Priority: Major
>             Fix For: 4.23.0
>
>
> When the named groups (or signature schemes) configured on 
> {{SSLContextParameters}} contain a duplicate or blank value, the whole 
> configured list is silently ignored and the default named groups of the JVM 
> are used instead.
> The JDK {{SSLParameters.setNamedGroups}} / {{setSignatureSchemes}} reject a 
> list with a blank or duplicate value (IllegalArgumentException), and 
> BaseSSLContextParameters (which calls them using reflection) ignores the 
> exception, so nothing is configured and no error or warning is logged. For 
> example {{[secp384r1, secp384r1]}} or {{[secp384r1, ""]}} results in all the 
> default groups of the JVM (x25519, secp256r1, ..., ffdhe2048, ...).
> This happens easily from camel-main, as {{camel.ssl.namedGroups}} and 
> {{camel.ssl.signatureSchemes}} are split on comma without trimming: 
> {{secp384r1,,x25519}} (blank) or a copy/paste duplicate ignores the setting, 
> and {{secp384r1, x25519}} (space after comma) gives an unknown name " x25519".
> On JDK 17 (where the JDK does not have these methods) configured named groups 
> and signature schemes are also silently skipped.
> The fix trims the values and removes blank and duplicate values (keeping the 
> order), fails with a clear error if the JVM still rejects the values, and 
> logs a WARN when the JVM does not support configuring them.
> _Claude Code on behalf of Claus Ibsen_



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to