This is an automated email from the ASF dual-hosted git repository.
davsclaus pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/camel.git
The following commit(s) were added to refs/heads/main by this push:
new 960f69708939 CAMEL-25105: camel-netty - The client authentication of
sslContextParameters is overridden by needClientAuth=false (#27009)
960f69708939 is described below
commit 960f69708939a9c921c38383ce3e0b7dde78a4a9
Author: Claus Ibsen <[email protected]>
AuthorDate: Mon Sep 28 22:43:47 2026 +0200
CAMEL-25105: camel-netty - The client authentication of
sslContextParameters is overridden by needClientAuth=false (#27009)
Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
Signed-off-by: Claus Ibsen <[email protected]>
---
.../netty/http/HttpServerInitializerFactory.java | 6 +-
.../http/HttpServerSharedInitializerFactory.java | 6 +-
.../netty/DefaultServerInitializerFactory.java | 6 +-
.../NettySSLContextParametersClientAuthTest.java | 111 +++++++++++++++++++++
.../ROOT/pages/camel-4x-upgrade-guide-4_23.adoc | 7 ++
5 files changed, 133 insertions(+), 3 deletions(-)
diff --git
a/components/camel-netty-http/src/main/java/org/apache/camel/component/netty/http/HttpServerInitializerFactory.java
b/components/camel-netty-http/src/main/java/org/apache/camel/component/netty/http/HttpServerInitializerFactory.java
index 982fad1dcbe8..e399cba9b811 100644
---
a/components/camel-netty-http/src/main/java/org/apache/camel/component/netty/http/HttpServerInitializerFactory.java
+++
b/components/camel-netty-http/src/main/java/org/apache/camel/component/netty/http/HttpServerInitializerFactory.java
@@ -171,7 +171,11 @@ public class HttpServerInitializerFactory extends
ServerInitializerFactory {
} else if (sslContext != null) {
SSLEngine engine = sslContext.createSSLEngine();
engine.setUseClientMode(false);
-
engine.setNeedClientAuth(consumer.getConfiguration().isNeedClientAuth());
+ if (consumer.getConfiguration().isNeedClientAuth()) {
+ // only when enabled, to keep the client authentication from
the sslContextParameters (such as
+ // REQUIRE or WANT) when needClientAuth is not enabled
+ engine.setNeedClientAuth(true);
+ }
if (consumer.getConfiguration().isHostnameVerification()) {
SSLParameters sslParams = engine.getSSLParameters();
sslParams.setEndpointIdentificationAlgorithm("HTTPS");
diff --git
a/components/camel-netty-http/src/main/java/org/apache/camel/component/netty/http/HttpServerSharedInitializerFactory.java
b/components/camel-netty-http/src/main/java/org/apache/camel/component/netty/http/HttpServerSharedInitializerFactory.java
index 110d611bbdc7..ce3a28a90e7a 100644
---
a/components/camel-netty-http/src/main/java/org/apache/camel/component/netty/http/HttpServerSharedInitializerFactory.java
+++
b/components/camel-netty-http/src/main/java/org/apache/camel/component/netty/http/HttpServerSharedInitializerFactory.java
@@ -134,7 +134,11 @@ public class HttpServerSharedInitializerFactory extends
HttpServerInitializerFac
} else if (sslContext != null) {
SSLEngine engine = sslContext.createSSLEngine();
engine.setUseClientMode(false);
- engine.setNeedClientAuth(configuration.isNeedClientAuth());
+ if (configuration.isNeedClientAuth()) {
+ // only when enabled, to keep the client authentication from
the sslContextParameters (such as
+ // REQUIRE or WANT) when needClientAuth is not enabled
+ engine.setNeedClientAuth(true);
+ }
if (configuration.getSslContextParameters() == null) {
// just set the enabledProtocols if the SslContextParameter
doesn't set
engine.setEnabledProtocols(configuration.getEnabledProtocols().split(","));
diff --git
a/components/camel-netty/src/main/java/org/apache/camel/component/netty/DefaultServerInitializerFactory.java
b/components/camel-netty/src/main/java/org/apache/camel/component/netty/DefaultServerInitializerFactory.java
index 88e347ff8c30..7a95835b2370 100644
---
a/components/camel-netty/src/main/java/org/apache/camel/component/netty/DefaultServerInitializerFactory.java
+++
b/components/camel-netty/src/main/java/org/apache/camel/component/netty/DefaultServerInitializerFactory.java
@@ -140,7 +140,11 @@ public class DefaultServerInitializerFactory extends
ServerInitializerFactory {
} else if (sslContext != null) {
SSLEngine engine = sslContext.createSSLEngine();
engine.setUseClientMode(consumer.getConfiguration().isClientMode());
-
engine.setNeedClientAuth(consumer.getConfiguration().isNeedClientAuth());
+ if (consumer.getConfiguration().isNeedClientAuth()) {
+ // only when enabled, to keep the client authentication from
the sslContextParameters (such as
+ // REQUIRE or WANT) when needClientAuth is not enabled
+ engine.setNeedClientAuth(true);
+ }
if (consumer.getConfiguration().isHostnameVerification()) {
SSLParameters sslParams = engine.getSSLParameters();
sslParams.setEndpointIdentificationAlgorithm("HTTPS");
diff --git
a/components/camel-netty/src/test/java/org/apache/camel/component/netty/NettySSLContextParametersClientAuthTest.java
b/components/camel-netty/src/test/java/org/apache/camel/component/netty/NettySSLContextParametersClientAuthTest.java
new file mode 100644
index 000000000000..73e605f96bb7
--- /dev/null
+++
b/components/camel-netty/src/test/java/org/apache/camel/component/netty/NettySSLContextParametersClientAuthTest.java
@@ -0,0 +1,111 @@
+/*
+ * Licensed to the Apache Software Foundation (ASF) under one or more
+ * contributor license agreements. See the NOTICE file distributed with
+ * this work for additional information regarding copyright ownership.
+ * The ASF licenses this file to You under the Apache License, Version 2.0
+ * (the "License"); you may not use this file except in compliance with
+ * the License. You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.apache.camel.component.netty;
+
+import org.apache.camel.BindToRegistry;
+import org.apache.camel.CamelExecutionException;
+import org.apache.camel.builder.RouteBuilder;
+import org.apache.camel.support.jsse.ClientAuthentication;
+import org.apache.camel.support.jsse.KeyManagersParameters;
+import org.apache.camel.support.jsse.KeyStoreParameters;
+import org.apache.camel.support.jsse.SSLContextParameters;
+import org.apache.camel.support.jsse.SSLContextServerParameters;
+import org.apache.camel.support.jsse.TrustManagersParameters;
+import org.junit.jupiter.api.Test;
+import org.junit.jupiter.api.condition.DisabledIfSystemProperty;
+
+import static org.junit.jupiter.api.Assertions.assertEquals;
+import static org.junit.jupiter.api.Assertions.assertThrows;
+
+/**
+ * The client authentication (REQUIRE) of the sslContextParameters is used,
also when needClientAuth is not enabled.
+ */
+@DisabledIfSystemProperty(named = "java.vendor", matches = ".*ibm.*")
+public class NettySSLContextParametersClientAuthTest extends BaseNettyTest {
+
+ private KeyStoreParameters keyStore() {
+ KeyStoreParameters ksp = new KeyStoreParameters();
+
ksp.setResource(this.getClass().getClassLoader().getResource("keystore.jks").toString());
+ ksp.setPassword("changeit");
+ return ksp;
+ }
+
+ private KeyManagersParameters keyManagers() {
+ KeyManagersParameters kmp = new KeyManagersParameters();
+ kmp.setKeyPassword("changeit");
+ kmp.setKeyStore(keyStore());
+ return kmp;
+ }
+
+ private TrustManagersParameters trustManagers() {
+ TrustManagersParameters tmp = new TrustManagersParameters();
+ tmp.setKeyStore(keyStore());
+ return tmp;
+ }
+
+ @BindToRegistry("serverParameters")
+ public SSLContextParameters serverParameters() {
+ SSLContextServerParameters scsp = new SSLContextServerParameters();
+ scsp.setClientAuthentication(ClientAuthentication.REQUIRE.name());
+
+ SSLContextParameters scp = new SSLContextParameters();
+ scp.setKeyManagers(keyManagers());
+ scp.setTrustManagers(trustManagers());
+ scp.setServerParameters(scsp);
+ return scp;
+ }
+
+ @BindToRegistry("clientParameters")
+ public SSLContextParameters clientParameters() {
+ SSLContextParameters scp = new SSLContextParameters();
+ scp.setKeyManagers(keyManagers());
+ scp.setTrustManagers(trustManagers());
+ return scp;
+ }
+
+ @BindToRegistry("noCertificateParameters")
+ public SSLContextParameters noCertificateParameters() {
+ SSLContextParameters scp = new SSLContextParameters();
+ scp.setTrustManagers(trustManagers());
+ return scp;
+ }
+
+ @Override
+ protected RouteBuilder createRouteBuilder() {
+ return new RouteBuilder() {
+ public void configure() {
+
from("netty:tcp://localhost:{{port}}?sync=true&ssl=true&sslContextParameters=#serverParameters")
+ .transform().constant("Bye World");
+ }
+ };
+ }
+
+ @Test
+ public void testClientWithCertificate() {
+ String response = template.requestBody(
+
"netty:tcp://localhost:{{port}}?sync=true&ssl=true&sslContextParameters=#clientParameters",
+ "Hello World", String.class);
+ assertEquals("Bye World", response);
+ }
+
+ @Test
+ public void testClientWithoutCertificate() {
+ assertThrows(CamelExecutionException.class, () -> template.requestBody(
+
"netty:tcp://localhost:{{port}}?sync=true&ssl=true&sslContextParameters=#noCertificateParameters",
+ "Hello World", String.class));
+ }
+}
diff --git
a/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_23.adoc
b/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_23.adoc
index eed76abd6567..bd51898ad190 100644
--- a/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_23.adoc
+++ b/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_23.adoc
@@ -3187,6 +3187,13 @@ it had no effect. The option is kept for backward
compatibility of existing endp
deprecated and will be removed in a future release. Routes that set
`maxRetryTimeout` can simply drop it;
behaviour is unchanged.
+=== camel-netty, camel-netty-http - client authentication of
sslContextParameters
+
+A Netty consumer using `sslContextParameters` now uses the client
authentication of its server parameters
+(`clientAuthentication` of `SSLContextServerParameters`, or
`camel.ssl.clientAuthentication` with global SSL), also
+when the `needClientAuth` option is not enabled. Previously
`needClientAuth=false` (the default) turned the client
+authentication off.
+
=== camel-saxon - external XML entity resolution disabled by default in XQuery
The XQuery language and the `xquery` component now build their default Saxon
`Configuration` with a