oscerd opened a new pull request, #27052:
URL: https://github.com/apache/camel/pull/27052

   ## CI Fix
   
   **Failed run:** https://github.com/apache/camel/actions/runs/34846241660 
(`build (17, false)` of Dependabot's #26411, `bouncycastle-version` 1.85 → 
1.86; the JDK 25 job was cancelled with it)
   
   This PR carries the same version bump together with the `camel-pqc` changes 
it needs, so #26411 can be closed once this is merged (Dependabot closes it by 
itself when `main` is on 1.86).
   
   ## Description
   
   Bouncy Castle 1.86 removes the legacy post-quantum implementations and 
parameter-spec classes from the `BCPQC` provider. The CI log shows the first 9 
compile errors, because javac stops at the unresolved imports; forcing it past 
them gives 30 errors in total (24 in 7 main files, 6 in 3 test files), all in 
`camel-pqc`. None of the other modules using Bouncy Castle imports a class that 
1.86 removed.
   
   ### Errors Fixed
   
   - **`CMCEParameterSpec` / `FrodoParameterSpec` not found.** Classic McEliece 
and FrodoKEM are now only served by the `BC` provider, which already had them 
in 1.85. `PQCKeyEncapsulationAlgorithms` maps `CMCE` and `FRODO` to `CMCE` and 
`FrodoKEM` on `BC`, and the default materials, the tests and 
`PQCParameterSpecResolver` use `org.bouncycastle.jcajce.spec.CMCEParameterSpec` 
and `FrodoKEMParameterSpec`. KEM generation/extraction and key encoding 
round-trip on both 1.85 and 1.86.
   - **Default parameter sets no longer available.** `KeyAlgorithmSupport` and 
the AWS Secrets Manager and HashiCorp Vault key lifecycle managers defaulted to 
`mceliece348864` and `frodokem640aes`, which the `BC` implementation does not 
have. They now default to `mceliece460896` and `frodokem976aes`.
   - **`DilithiumParameterSpec`, `SPHINCSPlusParameterSpec`, 
`KyberParameterSpec` not found.** Since the Bouncy Castle 1.85 adaptation 
`DILITHIUM`, `SPHINCSPLUS` and `KYBER` generate ML-DSA, SLH-DSA and ML-KEM 
keys, so `PQCParameterSpecResolver` now resolves them with 
`MLDSAParameterSpec`, `SLHDSAParameterSpec` and `MLKEMParameterSpec`. This also 
fixes a latent bug: on 1.85 the legacy Dilithium and SPHINCS+ specs were handed 
to the ML-DSA and SLH-DSA generators, which reject them (`unknown parameter set 
name: DILITHIUM3`), so a `DILITHIUM` or `SPHINCSPLUS` endpoint configured with 
`parameterSpec` could not generate its key. The `kyber512/768/1024` names keep 
working, as ML-KEM accepts them as aliases.
   - **`PicnicParameterSpec` not found.** Bouncy Castle 1.86 no longer ships 
Picnic at all: no provider registers it and no 1.86 jar contains a Picnic class 
(1.85 had 40). The `PICNIC` signature algorithm, `PQCDefaultPicnicMaterial` and 
the two Picnic tests are removed; `PQCAlgorithmId.PICNIC` stays as a reserved 
identifier.
   
   ### Breaking changes (documented in the 4.23 upgrade guide)
   
   - `PICNIC` is no longer a valid `signatureAlgorithm`, and 
`PQCSignatureAlgorithms.PICNIC` is gone.
   - Classic McEliece and FrodoKEM keys generated by the removed `BCPQC` 
implementations cannot be read by the `BC` provider, which rejects their 
`1.3.6.1.4.1.22554.5.1.x` / `5.2.x` algorithm identifiers (checked on 1.85 and 
1.86), so stored keys have to be regenerated. The same holds for Picnic keys.
   - `parameterSpec` rejects `mceliece348864*` and `frodokem640*`, and no 
longer resolves `dilithium2/3/5` for `DILITHIUM` (the ML-DSA names do).
   
   ### Deferred Issues
   
   - No ticket created. Follow-up outside this repository: 
`pqc-signature-action.kamelet.yaml` in apache/camel-kamelets still lists 
`PICNIC` in its `signatureAlgorithm` enum.
   
   ## Tests
   
   - `PQCParameterSpecResolverTest`: resolves the ML-DSA/SLH-DSA/ML-KEM names 
for `DILITHIUM`/`SPHINCSPLUS`/`KYBER` and the new Classic McEliece/FrodoKEM 
names; two parameterized tests check that the resolved spec initializes the 
`KeyPairGenerator` each algorithm is mapped to, which is the check the 
`DILITHIUM` and `SPHINCSPLUS` cases fail on 1.85; the dropped 
`mceliece348864`/`frodokem640aes` sets are rejected.
   - `camel-pqc` on Bouncy Castle 1.86: the 232 unit tests pass on JDK 21, and 
on JDK 25 the 232 unit tests (including the JDK 25-only 
`PQCKeyStoreJdk25KeyConversionTest`) and the 18 integration tests (AWS Secrets 
Manager and HashiCorp Vault key lifecycle, Testcontainers) pass.
   - The other modules using `bouncycastle-version` pass on JDK 17 against 
1.86: `camel-as2-api` (104), `camel-as2` (13 + 111 ITs), `camel-asn1` (16), 
`camel-crypto-pgp` (71), `camel-fop` (10), `camel-jsch` (14 + 7 ITs), 
`camel-pdf` (10), `camel-ssh` (39), `camel-xmlsecurity` (199), 
`camel-mina-sftp` (26 + 267 ITs) and `camel-ftp` (80 + 372 ITs). The one 
`camel-ftp` error, `FtpProducerHealthCheckIT`, is locale-dependent and 
unrelated: it asserts the English `Connection refused` message, fails the same 
way with Bouncy Castle 1.85 on a non-English locale, and passes with an English 
one.
   - The full reactor builds with `mvn clean install -DskipTests`; the only 
regenerated changes are the catalog copies of the `pqc` metadata and docs.
   
   ## Documentation
   
   - `pqc-component.adoc`: parameter-set and provider tables updated, Picnic 
removed.
   - `pqc-key-lifecycle.adoc`: the examples used the removed 
`DilithiumParameterSpec`; the default parameter-set table is updated.
   - Upgrade-guide entry in `camel-4x-upgrade-guide-4_23.adoc`.
   
   _Claude Code on behalf of oscerd_
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to