This is an automated email from the ASF dual-hosted git repository.
davsclaus pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/camel.git
The following commit(s) were added to refs/heads/main by this push:
new 3e7c7cd0d997 CAMEL-25104: camel-core - SSLContextParameters should use
TLSv1.2 as minimum protocol by default (#27008)
3e7c7cd0d997 is described below
commit 3e7c7cd0d997bd8c6e872e10aa704a60f79a55d9
Author: Claus Ibsen <[email protected]>
AuthorDate: Mon Sep 28 22:43:37 2026 +0200
CAMEL-25104: camel-core - SSLContextParameters should use TLSv1.2 as
minimum protocol by default (#27008)
Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
Signed-off-by: Claus Ibsen <[email protected]>
---
.../support/jsse/BaseSSLContextParameters.java | 12 ++--
.../SSLContextParametersDefaultProtocolsTest.java | 66 ++++++++++++++++++++++
.../ROOT/pages/camel-4x-upgrade-guide-4_23.adoc | 11 ++++
.../ROOT/pages/camel-configuration-utilities.adoc | 6 +-
4 files changed, 88 insertions(+), 7 deletions(-)
diff --git
a/core/camel-api/src/main/java/org/apache/camel/support/jsse/BaseSSLContextParameters.java
b/core/camel-api/src/main/java/org/apache/camel/support/jsse/BaseSSLContextParameters.java
index aec871e93f50..8ddc4ab59238 100644
---
a/core/camel-api/src/main/java/org/apache/camel/support/jsse/BaseSSLContextParameters.java
+++
b/core/camel-api/src/main/java/org/apache/camel/support/jsse/BaseSSLContextParameters.java
@@ -65,13 +65,13 @@ public abstract class BaseSSLContextParameters extends
JsseParameters {
= List.of(".*");
protected static final List<String> DEFAULT_CIPHER_SUITES_FILTER_EXCLUDE
- = List.of(".*_NULL_.*", ".*_anon_.*", ".*_EXPORT_.*", ".*_DES_.*",
".*MD5", ".*RC4.*");
+ = List.of(".*_NULL_.*", ".*_anon_.*", ".*_EXPORT_.*", ".*_DES_.*",
".*_3DES_.*", ".*MD5", ".*RC4.*");
protected static final List<String>
DEFAULT_SECURE_SOCKET_PROTOCOLS_FILTER_INCLUDE
= List.of(".*");
protected static final List<String>
DEFAULT_SECURE_SOCKET_PROTOCOLS_FILTER_EXCLUDE
- = List.of("SSL.*");
+ = List.of("SSL.*", "TLSv1", "TLSv1\\.1");
private static final Logger LOG =
LoggerFactory.getLogger(BaseSSLContextParameters.class);
@@ -965,7 +965,7 @@ public abstract class BaseSSLContextParameters extends
JsseParameters {
public SSLServerSocket configure(SSLServerSocket socket) {
Collection<String> filteredCipherSuites =
BaseSSLContextParameters.this
- .filter(enabledCipherSuites,
Arrays.asList(socket.getSupportedCipherSuites()),
+ .filter(enabledCipherSuites,
Arrays.asList(socket.getSSLParameters().getCipherSuites()),
Arrays.asList(socket.getEnabledCipherSuites()),
enabledCipherSuitePatterns,
defaultEnabledCipherSuitePatterns,
!allowPassthrough);
@@ -975,7 +975,7 @@ public abstract class BaseSSLContextParameters extends
JsseParameters {
socket,
enabledCipherSuites,
enabledCipherSuitePatterns,
- socket.getSupportedCipherSuites(),
+ socket.getSSLParameters().getCipherSuites(),
socket.getEnabledCipherSuites(),
defaultEnabledCipherSuitePatterns,
filteredCipherSuites);
@@ -984,7 +984,7 @@ public abstract class BaseSSLContextParameters extends
JsseParameters {
socket.setEnabledCipherSuites(filteredCipherSuites.toArray(new
String[0]));
Collection<String> filteredSecureSocketProtocols =
BaseSSLContextParameters.this
- .filter(enabledSecureSocketProtocols,
Arrays.asList(socket.getSupportedProtocols()),
+ .filter(enabledSecureSocketProtocols,
Arrays.asList(socket.getSSLParameters().getProtocols()),
Arrays.asList(socket.getEnabledProtocols()),
enabledSecureSocketProtocolsPatterns,
defaultEnabledSecureSocketProtocolsPatterns,
!allowPassthrough);
@@ -994,7 +994,7 @@ public abstract class BaseSSLContextParameters extends
JsseParameters {
socket,
enabledSecureSocketProtocols,
enabledSecureSocketProtocolsPatterns,
- socket.getSupportedProtocols(),
+ socket.getSSLParameters().getProtocols(),
socket.getEnabledProtocols(),
defaultEnabledSecureSocketProtocolsPatterns,
filteredSecureSocketProtocols);
diff --git
a/core/camel-core/src/test/java/org/apache/camel/support/jsse/SSLContextParametersDefaultProtocolsTest.java
b/core/camel-core/src/test/java/org/apache/camel/support/jsse/SSLContextParametersDefaultProtocolsTest.java
new file mode 100644
index 000000000000..90f5cf398a12
--- /dev/null
+++
b/core/camel-core/src/test/java/org/apache/camel/support/jsse/SSLContextParametersDefaultProtocolsTest.java
@@ -0,0 +1,66 @@
+/*
+ * Licensed to the Apache Software Foundation (ASF) under one or more
+ * contributor license agreements. See the NOTICE file distributed with
+ * this work for additional information regarding copyright ownership.
+ * The ASF licenses this file to You under the Apache License, Version 2.0
+ * (the "License"); you may not use this file except in compliance with
+ * the License. You may obtain a copy of the License at
+ *
+ * http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.apache.camel.support.jsse;
+
+import java.util.List;
+
+import javax.net.ssl.SSLContext;
+import javax.net.ssl.SSLEngine;
+import javax.net.ssl.SSLServerSocket;
+import javax.net.ssl.SSLSocket;
+
+import org.junit.jupiter.api.Test;
+
+import static org.junit.jupiter.api.Assertions.assertEquals;
+import static org.junit.jupiter.api.Assertions.assertFalse;
+import static org.junit.jupiter.api.Assertions.assertTrue;
+
+public class SSLContextParametersDefaultProtocolsTest {
+
+ @Test
+ public void testDefaultProtocolsAreTls12OrNewer() throws Exception {
+ SSLContext context = new SSLContextParameters().createSSLContext(null);
+
+ SSLEngine engine = context.createSSLEngine();
+ SSLSocket socket = (SSLSocket)
context.getSocketFactory().createSocket();
+ SSLServerSocket serverSocket = (SSLServerSocket)
context.getServerSocketFactory().createServerSocket();
+
+ for (String[] protocols : List.of(engine.getEnabledProtocols(),
socket.getEnabledProtocols(),
+ serverSocket.getEnabledProtocols())) {
+ List<String> list = List.of(protocols);
+ assertFalse(list.isEmpty());
+ assertFalse(list.contains("TLSv1"), list.toString());
+ assertFalse(list.contains("TLSv1.1"), list.toString());
+ assertTrue(list.contains("TLSv1.2") || list.contains("TLSv1.3"),
list.toString());
+ }
+
+ // the server socket uses the same protocols and cipher suites as the
socket and engine
+ assertEquals(List.of(engine.getEnabledProtocols()),
List.of(serverSocket.getEnabledProtocols()));
+ assertEquals(List.of(engine.getEnabledCipherSuites()),
List.of(serverSocket.getEnabledCipherSuites()));
+ }
+
+ @Test
+ public void testExplicitOlderProtocol() throws Exception {
+ SSLContextParameters scp = new SSLContextParameters();
+ SecureSocketProtocolsParameters protocols = new
SecureSocketProtocolsParameters();
+ protocols.setSecureSocketProtocol(List.of("TLSv1.2"));
+ scp.setSecureSocketProtocols(protocols);
+
+ SSLEngine engine = scp.createSSLContext(null).createSSLEngine();
+ assertEquals(List.of("TLSv1.2"),
List.of(engine.getEnabledProtocols()));
+ }
+}
diff --git
a/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_23.adoc
b/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_23.adoc
index 659a9d94dcaa..eed76abd6567 100644
--- a/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_23.adoc
+++ b/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_23.adoc
@@ -3167,6 +3167,17 @@ This is a bug fix (CAMEL-24747). Routes that relied on
`toD` passing the encoded
component will now see the original raw value instead. For all other
components (`useRawUri()` returns
`false`), behaviour is unchanged.
+=== camel-core - default TLS protocols and cipher suites of
SSLContextParameters
+
+The default secure socket protocols filter of `SSLContextParameters` now also
excludes `TLSv1` and `TLSv1.1` (so
+`TLSv1.2` is the minimum), and the default cipher suites filter also excludes
the `3DES` cipher suites. The default
+filters of an `SSLServerSocket` are now applied over the default (enabled)
protocols and cipher suites of the JVM, as
+they already were for an `SSLSocket` and `SSLEngine`. Previously they were
applied over all the supported protocols
+and cipher suites, which enabled `TLSv1` and `TLSv1.1` on a server socket
(unless disabled in the JVM security
+configuration).
+
+To use an older protocol (not recommended) configure it explicitly using
`secureSocketProtocols`.
+
=== camel-elasticsearch, camel-opensearch - the maxRetryTimeout option is
deprecated
The `maxRetryTimeout` endpoint and component option is deprecated in both
`camel-elasticsearch` and
diff --git
a/docs/user-manual/modules/ROOT/pages/camel-configuration-utilities.adoc
b/docs/user-manual/modules/ROOT/pages/camel-configuration-utilities.adoc
index 1b446d28d1be..51284fe306cd 100644
--- a/docs/user-manual/modules/ROOT/pages/camel-configuration-utilities.adoc
+++ b/docs/user-manual/modules/ROOT/pages/camel-configuration-utilities.adoc
@@ -89,7 +89,7 @@ present, the default patterns applied are:
[source,text]
----
Includes .\*;
-Excludes .*_NULL_.*, .\*_anon_.*, .\*DES.*, .\*EXPORT.*, .\*MD5, .*RC4.*
+Excludes .*_NULL_.*, .\*_anon_.*, .\*_EXPORT_.*, .\*_DES_.*, .\*_3DES_.*,
.\*MD5, .*RC4.*
----
secureSocketProtocols::
@@ -113,8 +113,12 @@ are:
[source,text]
----
Includes .*
+Excludes SSL.*, TLSv1, TLSv1\.1
----
+This means TLSv1.2 is the minimum protocol by default. To enable an older
protocol (not recommended) it must
+be configured explicitly in secureSocketProtocols.
+
namedGroups::
This optional property represents a collection of explicitly named
TLS named groups (key exchange algorithms) to enable on both the client