This is an automated email from the ASF dual-hosted git repository.

davsclaus pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/camel.git


The following commit(s) were added to refs/heads/main by this push:
     new 3e7c7cd0d997 CAMEL-25104: camel-core - SSLContextParameters should use 
TLSv1.2 as minimum protocol by default (#27008)
3e7c7cd0d997 is described below

commit 3e7c7cd0d997bd8c6e872e10aa704a60f79a55d9
Author: Claus Ibsen <[email protected]>
AuthorDate: Mon Sep 28 22:43:37 2026 +0200

    CAMEL-25104: camel-core - SSLContextParameters should use TLSv1.2 as 
minimum protocol by default (#27008)
    
    Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
    Signed-off-by: Claus Ibsen <[email protected]>
---
 .../support/jsse/BaseSSLContextParameters.java     | 12 ++--
 .../SSLContextParametersDefaultProtocolsTest.java  | 66 ++++++++++++++++++++++
 .../ROOT/pages/camel-4x-upgrade-guide-4_23.adoc    | 11 ++++
 .../ROOT/pages/camel-configuration-utilities.adoc  |  6 +-
 4 files changed, 88 insertions(+), 7 deletions(-)

diff --git 
a/core/camel-api/src/main/java/org/apache/camel/support/jsse/BaseSSLContextParameters.java
 
b/core/camel-api/src/main/java/org/apache/camel/support/jsse/BaseSSLContextParameters.java
index aec871e93f50..8ddc4ab59238 100644
--- 
a/core/camel-api/src/main/java/org/apache/camel/support/jsse/BaseSSLContextParameters.java
+++ 
b/core/camel-api/src/main/java/org/apache/camel/support/jsse/BaseSSLContextParameters.java
@@ -65,13 +65,13 @@ public abstract class BaseSSLContextParameters extends 
JsseParameters {
             = List.of(".*");
 
     protected static final List<String> DEFAULT_CIPHER_SUITES_FILTER_EXCLUDE
-            = List.of(".*_NULL_.*", ".*_anon_.*", ".*_EXPORT_.*", ".*_DES_.*", 
".*MD5", ".*RC4.*");
+            = List.of(".*_NULL_.*", ".*_anon_.*", ".*_EXPORT_.*", ".*_DES_.*", 
".*_3DES_.*", ".*MD5", ".*RC4.*");
 
     protected static final List<String> 
DEFAULT_SECURE_SOCKET_PROTOCOLS_FILTER_INCLUDE
             = List.of(".*");
 
     protected static final List<String> 
DEFAULT_SECURE_SOCKET_PROTOCOLS_FILTER_EXCLUDE
-            = List.of("SSL.*");
+            = List.of("SSL.*", "TLSv1", "TLSv1\\.1");
 
     private static final Logger LOG = 
LoggerFactory.getLogger(BaseSSLContextParameters.class);
 
@@ -965,7 +965,7 @@ public abstract class BaseSSLContextParameters extends 
JsseParameters {
             public SSLServerSocket configure(SSLServerSocket socket) {
 
                 Collection<String> filteredCipherSuites = 
BaseSSLContextParameters.this
-                        .filter(enabledCipherSuites, 
Arrays.asList(socket.getSupportedCipherSuites()),
+                        .filter(enabledCipherSuites, 
Arrays.asList(socket.getSSLParameters().getCipherSuites()),
                                 Arrays.asList(socket.getEnabledCipherSuites()),
                                 enabledCipherSuitePatterns, 
defaultEnabledCipherSuitePatterns,
                                 !allowPassthrough);
@@ -975,7 +975,7 @@ public abstract class BaseSSLContextParameters extends 
JsseParameters {
                             socket,
                             enabledCipherSuites,
                             enabledCipherSuitePatterns,
-                            socket.getSupportedCipherSuites(),
+                            socket.getSSLParameters().getCipherSuites(),
                             socket.getEnabledCipherSuites(),
                             defaultEnabledCipherSuitePatterns,
                             filteredCipherSuites);
@@ -984,7 +984,7 @@ public abstract class BaseSSLContextParameters extends 
JsseParameters {
                 socket.setEnabledCipherSuites(filteredCipherSuites.toArray(new 
String[0]));
 
                 Collection<String> filteredSecureSocketProtocols = 
BaseSSLContextParameters.this
-                        .filter(enabledSecureSocketProtocols, 
Arrays.asList(socket.getSupportedProtocols()),
+                        .filter(enabledSecureSocketProtocols, 
Arrays.asList(socket.getSSLParameters().getProtocols()),
                                 Arrays.asList(socket.getEnabledProtocols()),
                                 enabledSecureSocketProtocolsPatterns, 
defaultEnabledSecureSocketProtocolsPatterns,
                                 !allowPassthrough);
@@ -994,7 +994,7 @@ public abstract class BaseSSLContextParameters extends 
JsseParameters {
                             socket,
                             enabledSecureSocketProtocols,
                             enabledSecureSocketProtocolsPatterns,
-                            socket.getSupportedProtocols(),
+                            socket.getSSLParameters().getProtocols(),
                             socket.getEnabledProtocols(),
                             defaultEnabledSecureSocketProtocolsPatterns,
                             filteredSecureSocketProtocols);
diff --git 
a/core/camel-core/src/test/java/org/apache/camel/support/jsse/SSLContextParametersDefaultProtocolsTest.java
 
b/core/camel-core/src/test/java/org/apache/camel/support/jsse/SSLContextParametersDefaultProtocolsTest.java
new file mode 100644
index 000000000000..90f5cf398a12
--- /dev/null
+++ 
b/core/camel-core/src/test/java/org/apache/camel/support/jsse/SSLContextParametersDefaultProtocolsTest.java
@@ -0,0 +1,66 @@
+/*
+ * Licensed to the Apache Software Foundation (ASF) under one or more
+ * contributor license agreements.  See the NOTICE file distributed with
+ * this work for additional information regarding copyright ownership.
+ * The ASF licenses this file to You under the Apache License, Version 2.0
+ * (the "License"); you may not use this file except in compliance with
+ * the License.  You may obtain a copy of the License at
+ *
+ *      http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.apache.camel.support.jsse;
+
+import java.util.List;
+
+import javax.net.ssl.SSLContext;
+import javax.net.ssl.SSLEngine;
+import javax.net.ssl.SSLServerSocket;
+import javax.net.ssl.SSLSocket;
+
+import org.junit.jupiter.api.Test;
+
+import static org.junit.jupiter.api.Assertions.assertEquals;
+import static org.junit.jupiter.api.Assertions.assertFalse;
+import static org.junit.jupiter.api.Assertions.assertTrue;
+
+public class SSLContextParametersDefaultProtocolsTest {
+
+    @Test
+    public void testDefaultProtocolsAreTls12OrNewer() throws Exception {
+        SSLContext context = new SSLContextParameters().createSSLContext(null);
+
+        SSLEngine engine = context.createSSLEngine();
+        SSLSocket socket = (SSLSocket) 
context.getSocketFactory().createSocket();
+        SSLServerSocket serverSocket = (SSLServerSocket) 
context.getServerSocketFactory().createServerSocket();
+
+        for (String[] protocols : List.of(engine.getEnabledProtocols(), 
socket.getEnabledProtocols(),
+                serverSocket.getEnabledProtocols())) {
+            List<String> list = List.of(protocols);
+            assertFalse(list.isEmpty());
+            assertFalse(list.contains("TLSv1"), list.toString());
+            assertFalse(list.contains("TLSv1.1"), list.toString());
+            assertTrue(list.contains("TLSv1.2") || list.contains("TLSv1.3"), 
list.toString());
+        }
+
+        // the server socket uses the same protocols and cipher suites as the 
socket and engine
+        assertEquals(List.of(engine.getEnabledProtocols()), 
List.of(serverSocket.getEnabledProtocols()));
+        assertEquals(List.of(engine.getEnabledCipherSuites()), 
List.of(serverSocket.getEnabledCipherSuites()));
+    }
+
+    @Test
+    public void testExplicitOlderProtocol() throws Exception {
+        SSLContextParameters scp = new SSLContextParameters();
+        SecureSocketProtocolsParameters protocols = new 
SecureSocketProtocolsParameters();
+        protocols.setSecureSocketProtocol(List.of("TLSv1.2"));
+        scp.setSecureSocketProtocols(protocols);
+
+        SSLEngine engine = scp.createSSLContext(null).createSSLEngine();
+        assertEquals(List.of("TLSv1.2"), 
List.of(engine.getEnabledProtocols()));
+    }
+}
diff --git 
a/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_23.adoc 
b/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_23.adoc
index 659a9d94dcaa..eed76abd6567 100644
--- a/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_23.adoc
+++ b/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_23.adoc
@@ -3167,6 +3167,17 @@ This is a bug fix (CAMEL-24747). Routes that relied on 
`toD` passing the encoded
 component will now see the original raw value instead. For all other 
components (`useRawUri()` returns
 `false`), behaviour is unchanged.
 
+=== camel-core - default TLS protocols and cipher suites of 
SSLContextParameters
+
+The default secure socket protocols filter of `SSLContextParameters` now also 
excludes `TLSv1` and `TLSv1.1` (so
+`TLSv1.2` is the minimum), and the default cipher suites filter also excludes 
the `3DES` cipher suites. The default
+filters of an `SSLServerSocket` are now applied over the default (enabled) 
protocols and cipher suites of the JVM, as
+they already were for an `SSLSocket` and `SSLEngine`. Previously they were 
applied over all the supported protocols
+and cipher suites, which enabled `TLSv1` and `TLSv1.1` on a server socket 
(unless disabled in the JVM security
+configuration).
+
+To use an older protocol (not recommended) configure it explicitly using 
`secureSocketProtocols`.
+
 === camel-elasticsearch, camel-opensearch - the maxRetryTimeout option is 
deprecated
 
 The `maxRetryTimeout` endpoint and component option is deprecated in both 
`camel-elasticsearch` and
diff --git 
a/docs/user-manual/modules/ROOT/pages/camel-configuration-utilities.adoc 
b/docs/user-manual/modules/ROOT/pages/camel-configuration-utilities.adoc
index 1b446d28d1be..51284fe306cd 100644
--- a/docs/user-manual/modules/ROOT/pages/camel-configuration-utilities.adoc
+++ b/docs/user-manual/modules/ROOT/pages/camel-configuration-utilities.adoc
@@ -89,7 +89,7 @@ present, the default patterns applied are:
 [source,text]
 ----
 Includes .\*;
-Excludes .*_NULL_.*, .\*_anon_.*, .\*DES.*, .\*EXPORT.*, .\*MD5, .*RC4.*
+Excludes .*_NULL_.*, .\*_anon_.*, .\*_EXPORT_.*, .\*_DES_.*, .\*_3DES_.*, 
.\*MD5, .*RC4.*
 ----
 
 secureSocketProtocols::
@@ -113,8 +113,12 @@ are:
 [source,text]
 ----
 Includes .*
+Excludes SSL.*, TLSv1, TLSv1\.1
 ----
 
+This means TLSv1.2 is the minimum protocol by default. To enable an older 
protocol (not recommended) it must
+be configured explicitly in secureSocketProtocols.
+
 namedGroups::
 This optional property represents a collection of explicitly named
 TLS named groups (key exchange algorithms) to enable on both the client

Reply via email to