This is an automated email from the ASF dual-hosted git repository.

davsclaus pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/camel.git


The following commit(s) were added to refs/heads/main by this push:
     new 960f69708939 CAMEL-25105: camel-netty - The client authentication of 
sslContextParameters is overridden by needClientAuth=false (#27009)
960f69708939 is described below

commit 960f69708939a9c921c38383ce3e0b7dde78a4a9
Author: Claus Ibsen <[email protected]>
AuthorDate: Mon Sep 28 22:43:47 2026 +0200

    CAMEL-25105: camel-netty - The client authentication of 
sslContextParameters is overridden by needClientAuth=false (#27009)
    
    Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
    Signed-off-by: Claus Ibsen <[email protected]>
---
 .../netty/http/HttpServerInitializerFactory.java   |   6 +-
 .../http/HttpServerSharedInitializerFactory.java   |   6 +-
 .../netty/DefaultServerInitializerFactory.java     |   6 +-
 .../NettySSLContextParametersClientAuthTest.java   | 111 +++++++++++++++++++++
 .../ROOT/pages/camel-4x-upgrade-guide-4_23.adoc    |   7 ++
 5 files changed, 133 insertions(+), 3 deletions(-)

diff --git 
a/components/camel-netty-http/src/main/java/org/apache/camel/component/netty/http/HttpServerInitializerFactory.java
 
b/components/camel-netty-http/src/main/java/org/apache/camel/component/netty/http/HttpServerInitializerFactory.java
index 982fad1dcbe8..e399cba9b811 100644
--- 
a/components/camel-netty-http/src/main/java/org/apache/camel/component/netty/http/HttpServerInitializerFactory.java
+++ 
b/components/camel-netty-http/src/main/java/org/apache/camel/component/netty/http/HttpServerInitializerFactory.java
@@ -171,7 +171,11 @@ public class HttpServerInitializerFactory extends 
ServerInitializerFactory {
         } else if (sslContext != null) {
             SSLEngine engine = sslContext.createSSLEngine();
             engine.setUseClientMode(false);
-            
engine.setNeedClientAuth(consumer.getConfiguration().isNeedClientAuth());
+            if (consumer.getConfiguration().isNeedClientAuth()) {
+                // only when enabled, to keep the client authentication from 
the sslContextParameters (such as
+                // REQUIRE or WANT) when needClientAuth is not enabled
+                engine.setNeedClientAuth(true);
+            }
             if (consumer.getConfiguration().isHostnameVerification()) {
                 SSLParameters sslParams = engine.getSSLParameters();
                 sslParams.setEndpointIdentificationAlgorithm("HTTPS");
diff --git 
a/components/camel-netty-http/src/main/java/org/apache/camel/component/netty/http/HttpServerSharedInitializerFactory.java
 
b/components/camel-netty-http/src/main/java/org/apache/camel/component/netty/http/HttpServerSharedInitializerFactory.java
index 110d611bbdc7..ce3a28a90e7a 100644
--- 
a/components/camel-netty-http/src/main/java/org/apache/camel/component/netty/http/HttpServerSharedInitializerFactory.java
+++ 
b/components/camel-netty-http/src/main/java/org/apache/camel/component/netty/http/HttpServerSharedInitializerFactory.java
@@ -134,7 +134,11 @@ public class HttpServerSharedInitializerFactory extends 
HttpServerInitializerFac
         } else if (sslContext != null) {
             SSLEngine engine = sslContext.createSSLEngine();
             engine.setUseClientMode(false);
-            engine.setNeedClientAuth(configuration.isNeedClientAuth());
+            if (configuration.isNeedClientAuth()) {
+                // only when enabled, to keep the client authentication from 
the sslContextParameters (such as
+                // REQUIRE or WANT) when needClientAuth is not enabled
+                engine.setNeedClientAuth(true);
+            }
             if (configuration.getSslContextParameters() == null) {
                 // just set the enabledProtocols if the SslContextParameter 
doesn't set
                 
engine.setEnabledProtocols(configuration.getEnabledProtocols().split(","));
diff --git 
a/components/camel-netty/src/main/java/org/apache/camel/component/netty/DefaultServerInitializerFactory.java
 
b/components/camel-netty/src/main/java/org/apache/camel/component/netty/DefaultServerInitializerFactory.java
index 88e347ff8c30..7a95835b2370 100644
--- 
a/components/camel-netty/src/main/java/org/apache/camel/component/netty/DefaultServerInitializerFactory.java
+++ 
b/components/camel-netty/src/main/java/org/apache/camel/component/netty/DefaultServerInitializerFactory.java
@@ -140,7 +140,11 @@ public class DefaultServerInitializerFactory extends 
ServerInitializerFactory {
         } else if (sslContext != null) {
             SSLEngine engine = sslContext.createSSLEngine();
             
engine.setUseClientMode(consumer.getConfiguration().isClientMode());
-            
engine.setNeedClientAuth(consumer.getConfiguration().isNeedClientAuth());
+            if (consumer.getConfiguration().isNeedClientAuth()) {
+                // only when enabled, to keep the client authentication from 
the sslContextParameters (such as
+                // REQUIRE or WANT) when needClientAuth is not enabled
+                engine.setNeedClientAuth(true);
+            }
             if (consumer.getConfiguration().isHostnameVerification()) {
                 SSLParameters sslParams = engine.getSSLParameters();
                 sslParams.setEndpointIdentificationAlgorithm("HTTPS");
diff --git 
a/components/camel-netty/src/test/java/org/apache/camel/component/netty/NettySSLContextParametersClientAuthTest.java
 
b/components/camel-netty/src/test/java/org/apache/camel/component/netty/NettySSLContextParametersClientAuthTest.java
new file mode 100644
index 000000000000..73e605f96bb7
--- /dev/null
+++ 
b/components/camel-netty/src/test/java/org/apache/camel/component/netty/NettySSLContextParametersClientAuthTest.java
@@ -0,0 +1,111 @@
+/*
+ * Licensed to the Apache Software Foundation (ASF) under one or more
+ * contributor license agreements.  See the NOTICE file distributed with
+ * this work for additional information regarding copyright ownership.
+ * The ASF licenses this file to You under the Apache License, Version 2.0
+ * (the "License"); you may not use this file except in compliance with
+ * the License.  You may obtain a copy of the License at
+ *
+ *      http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.apache.camel.component.netty;
+
+import org.apache.camel.BindToRegistry;
+import org.apache.camel.CamelExecutionException;
+import org.apache.camel.builder.RouteBuilder;
+import org.apache.camel.support.jsse.ClientAuthentication;
+import org.apache.camel.support.jsse.KeyManagersParameters;
+import org.apache.camel.support.jsse.KeyStoreParameters;
+import org.apache.camel.support.jsse.SSLContextParameters;
+import org.apache.camel.support.jsse.SSLContextServerParameters;
+import org.apache.camel.support.jsse.TrustManagersParameters;
+import org.junit.jupiter.api.Test;
+import org.junit.jupiter.api.condition.DisabledIfSystemProperty;
+
+import static org.junit.jupiter.api.Assertions.assertEquals;
+import static org.junit.jupiter.api.Assertions.assertThrows;
+
+/**
+ * The client authentication (REQUIRE) of the sslContextParameters is used, 
also when needClientAuth is not enabled.
+ */
+@DisabledIfSystemProperty(named = "java.vendor", matches = ".*ibm.*")
+public class NettySSLContextParametersClientAuthTest extends BaseNettyTest {
+
+    private KeyStoreParameters keyStore() {
+        KeyStoreParameters ksp = new KeyStoreParameters();
+        
ksp.setResource(this.getClass().getClassLoader().getResource("keystore.jks").toString());
+        ksp.setPassword("changeit");
+        return ksp;
+    }
+
+    private KeyManagersParameters keyManagers() {
+        KeyManagersParameters kmp = new KeyManagersParameters();
+        kmp.setKeyPassword("changeit");
+        kmp.setKeyStore(keyStore());
+        return kmp;
+    }
+
+    private TrustManagersParameters trustManagers() {
+        TrustManagersParameters tmp = new TrustManagersParameters();
+        tmp.setKeyStore(keyStore());
+        return tmp;
+    }
+
+    @BindToRegistry("serverParameters")
+    public SSLContextParameters serverParameters() {
+        SSLContextServerParameters scsp = new SSLContextServerParameters();
+        scsp.setClientAuthentication(ClientAuthentication.REQUIRE.name());
+
+        SSLContextParameters scp = new SSLContextParameters();
+        scp.setKeyManagers(keyManagers());
+        scp.setTrustManagers(trustManagers());
+        scp.setServerParameters(scsp);
+        return scp;
+    }
+
+    @BindToRegistry("clientParameters")
+    public SSLContextParameters clientParameters() {
+        SSLContextParameters scp = new SSLContextParameters();
+        scp.setKeyManagers(keyManagers());
+        scp.setTrustManagers(trustManagers());
+        return scp;
+    }
+
+    @BindToRegistry("noCertificateParameters")
+    public SSLContextParameters noCertificateParameters() {
+        SSLContextParameters scp = new SSLContextParameters();
+        scp.setTrustManagers(trustManagers());
+        return scp;
+    }
+
+    @Override
+    protected RouteBuilder createRouteBuilder() {
+        return new RouteBuilder() {
+            public void configure() {
+                
from("netty:tcp://localhost:{{port}}?sync=true&ssl=true&sslContextParameters=#serverParameters")
+                        .transform().constant("Bye World");
+            }
+        };
+    }
+
+    @Test
+    public void testClientWithCertificate() {
+        String response = template.requestBody(
+                
"netty:tcp://localhost:{{port}}?sync=true&ssl=true&sslContextParameters=#clientParameters",
+                "Hello World", String.class);
+        assertEquals("Bye World", response);
+    }
+
+    @Test
+    public void testClientWithoutCertificate() {
+        assertThrows(CamelExecutionException.class, () -> template.requestBody(
+                
"netty:tcp://localhost:{{port}}?sync=true&ssl=true&sslContextParameters=#noCertificateParameters",
+                "Hello World", String.class));
+    }
+}
diff --git 
a/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_23.adoc 
b/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_23.adoc
index eed76abd6567..bd51898ad190 100644
--- a/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_23.adoc
+++ b/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_23.adoc
@@ -3187,6 +3187,13 @@ it had no effect. The option is kept for backward 
compatibility of existing endp
 deprecated and will be removed in a future release. Routes that set 
`maxRetryTimeout` can simply drop it;
 behaviour is unchanged.
 
+=== camel-netty, camel-netty-http - client authentication of 
sslContextParameters
+
+A Netty consumer using `sslContextParameters` now uses the client 
authentication of its server parameters
+(`clientAuthentication` of `SSLContextServerParameters`, or 
`camel.ssl.clientAuthentication` with global SSL), also
+when the `needClientAuth` option is not enabled. Previously 
`needClientAuth=false` (the default) turned the client
+authentication off.
+
 === camel-saxon - external XML entity resolution disabled by default in XQuery
 
 The XQuery language and the `xquery` component now build their default Saxon 
`Configuration` with a

Reply via email to