davsclaus opened a new pull request, #27008: URL: https://github.com/apache/camel/pull/27008
Implements [CAMEL-25104](https://issues.apache.org/jira/browse/CAMEL-25104). The default filters of `SSLContextParameters` now use TLSv1.2 as the minimum protocol: - **Default protocols filter:** now also excludes `TLSv1` and `TLSv1.1`. Before, it only excluded `SSL.*`. - **Default cipher suites filter:** now also excludes `.*_3DES_.*`. The existing `.*_DES_.*` does not match the 3DES suites. - **`SSLServerSocket`:** the default filters are now applied over the JVM's default enabled protocols and cipher suites, as they already were for `SSLSocket` and `SSLEngine`. - Before, the server socket filtered over all supported protocols, so it enabled `[TLSv1.3, TLSv1.2, TLSv1.1, TLSv1]` on JDK 21/25 unless the JVM security configuration disabled them. An older protocol can still be configured explicitly with `secureSocketProtocols`. The documented default filters were outdated and are updated, and the upgrade guide has an entry. ## Tests - **New `SSLContextParametersDefaultProtocolsTest`:** - the default `SSLEngine`, `SSLSocket` and `SSLServerSocket` enable only TLSv1.2 or newer; - the server socket uses the same protocols and cipher suites as the engine; - an explicit protocol list is still used as-is. It fails without the fix. - **Existing tests:** the JSSE tests in camel-core pass. The change should be backported to the supported release lines (4.22.x and 4.18.x). _Claude Code on behalf of Claus Ibsen_ 🤖 Generated with [Claude Code](https://claude.com/claude-code) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
