This is an automated email from the ASF dual-hosted git repository.

oscerd pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/camel.git


The following commit(s) were added to refs/heads/main by this push:
     new ce623be66447 CAMEL-25409: camel-mongodb, camel-aws2-transcribe, 
camel-twitter - fix security metadata that does not match the code (#27482)
ce623be66447 is described below

commit ce623be6644756a7e06fe33b539f1d7617593c74
Author: Andrea Cosentino <[email protected]>
AuthorDate: Wed Oct 7 13:37:06 2026 +0200

    CAMEL-25409: camel-mongodb, camel-aws2-transcribe, camel-twitter - fix 
security metadata that does not match the code (#27482)
    
    A sweep of every catalog option against the security metadata the policy
    framework relies on found three options whose metadata contradicts what the
    code does. All three are metadata-only defects - the runtime default is the
    safe one in every case - but each defeats a mechanism meant to catch
    misconfiguration.
    
    - camel-mongodb: tlsAllowInvalidHostnames disables TLS hostname verification
      (MongoDbEndpoint calls invalidHostNameAllowed(true)) but was not marked
      security = "insecure:ssl", so camel.main.profile=prod did not refuse it.
      The 4.23 upgrade guide documents the startup change for prod-profile users
      and how to keep the setting through camel.security.allowedProperties.
    - camel-aws2-transcribe: trustAllCertificates declared defaultValue = "true"
      on a bare boolean field. This is a metadata-only correction with no
      behavioral change: the field has no initializer, so the runtime default 
was
      always false; only the advertised default in the catalog, the docs and the
      generated DSL builders was wrong.
    - camel-twitter: the component-level httpProxyPassword was not marked as a
      secret, although the endpoint-level twin in TwitterConfiguration is (it 
was
      already treated as sensitive at runtime through SensitiveUtils).
    
    SecurityUtilsTest covers the hostname-verification options so a future 
option
    of this kind cannot silently go unregistered.
    
    Co-Authored-By: Claude Opus 5 <[email protected]>
---
 .../org/apache/camel/catalog/components/aws2-transcribe.json  |  4 ++--
 .../org/apache/camel/catalog/components/mongodb.json          |  2 +-
 .../camel/catalog/components/twitter-directmessage.json       |  2 +-
 .../org/apache/camel/catalog/components/twitter-search.json   |  2 +-
 .../org/apache/camel/catalog/components/twitter-timeline.json |  2 +-
 .../camel/component/aws2/transcribe/aws2-transcribe.json      |  4 ++--
 .../component/aws2/transcribe/Transcribe2Configuration.java   |  2 +-
 .../META-INF/org/apache/camel/component/mongodb/mongodb.json  |  2 +-
 .../org/apache/camel/component/mongodb/MongoDbEndpoint.java   |  2 +-
 .../twitter/directmessage/twitter-directmessage.json          |  2 +-
 .../apache/camel/component/twitter/search/twitter-search.json |  2 +-
 .../camel/component/twitter/timeline/twitter-timeline.json    |  2 +-
 .../camel/component/twitter/AbstractTwitterComponent.java     |  2 +-
 .../src/main/java/org/apache/camel/util/SecurityUtils.java    |  3 +++
 .../test/java/org/apache/camel/util/SecurityUtilsTest.java    | 10 ++++++++++
 .../modules/ROOT/pages/camel-4x-upgrade-guide-4_23.adoc       | 11 +++++++++++
 .../component/dsl/Aws2TranscribeComponentBuilderFactory.java  |  2 +-
 .../endpoint/dsl/Transcribe2EndpointBuilderFactory.java       |  4 ++--
 18 files changed, 42 insertions(+), 18 deletions(-)

diff --git 
a/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/components/aws2-transcribe.json
 
b/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/components/aws2-transcribe.json
index 4fb1f99f040d..46f984f20ada 100644
--- 
a/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/components/aws2-transcribe.json
+++ 
b/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/components/aws2-transcribe.json
@@ -36,7 +36,7 @@
     "proxyProtocol": { "index": 9, "kind": "property", "displayName": "Proxy 
Protocol", "group": "producer", "label": "", "required": false, "type": "enum", 
"javaType": "software.amazon.awssdk.core.Protocol", "enum": [ "HTTP", "HTTPS" 
], "deprecated": false, "autowired": false, "secret": false, "defaultValue": 
"HTTPS", "configurationClass": 
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration", 
"configurationField": "configuration", "description": "To define a proxy proto 
[...]
     "region": { "index": 10, "kind": "property", "displayName": "Region", 
"group": "producer", "label": "", "required": false, "type": "string", 
"javaType": "java.lang.String", "deprecated": false, "autowired": false, 
"secret": false, "configurationClass": 
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration", 
"configurationField": "configuration", "description": "The region in which 
Transcribe client needs to work. When using this parameter, the configuration 
will expect [...]
     "transcribeClient": { "index": 11, "kind": "property", "displayName": 
"Transcribe Client", "group": "producer", "label": "", "required": false, 
"type": "object", "javaType": 
"software.amazon.awssdk.services.transcribe.TranscribeClient", "deprecated": 
false, "autowired": false, "secret": false, "configurationClass": 
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration", 
"configurationField": "configuration", "description": "To use a existing 
configured AWS Transcribe a [...]
-    "trustAllCertificates": { "index": 12, "kind": "property", "displayName": 
"Trust All Certificates", "group": "producer", "label": "", "required": false, 
"type": "boolean", "javaType": "boolean", "deprecated": false, "autowired": 
false, "secret": false, "security": "insecure:ssl", "defaultValue": true, 
"configurationClass": 
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration", 
"configurationField": "configuration", "description": "If we want to trust all 
certificates  [...]
+    "trustAllCertificates": { "index": 12, "kind": "property", "displayName": 
"Trust All Certificates", "group": "producer", "label": "", "required": false, 
"type": "boolean", "javaType": "boolean", "deprecated": false, "autowired": 
false, "secret": false, "security": "insecure:ssl", "defaultValue": false, 
"configurationClass": 
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration", 
"configurationField": "configuration", "description": "If we want to trust all 
certificates [...]
     "uriEndpointOverride": { "index": 13, "kind": "property", "displayName": 
"Uri Endpoint Override", "group": "producer", "label": "", "required": false, 
"type": "string", "javaType": "java.lang.String", "deprecated": false, 
"autowired": false, "secret": false, "configurationClass": 
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration", 
"configurationField": "configuration", "description": "Set the overriding uri 
endpoint. This option needs to be used in combination with [...]
     "useDefaultCredentialsProvider": { "index": 14, "kind": "property", 
"displayName": "Use Default Credentials Provider", "group": "producer", 
"label": "", "required": false, "type": "boolean", "javaType": "boolean", 
"deprecated": false, "autowired": false, "secret": false, "defaultValue": 
false, "configurationClass": 
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration", 
"configurationField": "configuration", "description": "Set whether the 
Transcribe client should expe [...]
     "useProfileCredentialsProvider": { "index": 15, "kind": "property", 
"displayName": "Use Profile Credentials Provider", "group": "producer", 
"label": "", "required": false, "type": "boolean", "javaType": "boolean", 
"deprecated": false, "autowired": false, "secret": false, "defaultValue": 
false, "configurationClass": 
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration", 
"configurationField": "configuration", "description": "Set whether the 
Transcribe client should expe [...]
@@ -85,7 +85,7 @@
     "proxyProtocol": { "index": 8, "kind": "parameter", "displayName": "Proxy 
Protocol", "group": "producer", "label": "", "required": false, "type": "enum", 
"javaType": "software.amazon.awssdk.core.Protocol", "enum": [ "HTTP", "HTTPS" 
], "deprecated": false, "autowired": false, "secret": false, "defaultValue": 
"HTTPS", "configurationClass": 
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration", 
"configurationField": "configuration", "description": "To define a proxy prot 
[...]
     "region": { "index": 9, "kind": "parameter", "displayName": "Region", 
"group": "producer", "label": "", "required": false, "type": "string", 
"javaType": "java.lang.String", "deprecated": false, "autowired": false, 
"secret": false, "configurationClass": 
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration", 
"configurationField": "configuration", "description": "The region in which 
Transcribe client needs to work. When using this parameter, the configuration 
will expect [...]
     "transcribeClient": { "index": 10, "kind": "parameter", "displayName": 
"Transcribe Client", "group": "producer", "label": "", "required": false, 
"type": "object", "javaType": 
"software.amazon.awssdk.services.transcribe.TranscribeClient", "deprecated": 
false, "autowired": false, "secret": false, "configurationClass": 
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration", 
"configurationField": "configuration", "description": "To use a existing 
configured AWS Transcribe  [...]
-    "trustAllCertificates": { "index": 11, "kind": "parameter", "displayName": 
"Trust All Certificates", "group": "producer", "label": "", "required": false, 
"type": "boolean", "javaType": "boolean", "deprecated": false, "autowired": 
false, "secret": false, "security": "insecure:ssl", "defaultValue": true, 
"configurationClass": 
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration", 
"configurationField": "configuration", "description": "If we want to trust all 
certificates [...]
+    "trustAllCertificates": { "index": 11, "kind": "parameter", "displayName": 
"Trust All Certificates", "group": "producer", "label": "", "required": false, 
"type": "boolean", "javaType": "boolean", "deprecated": false, "autowired": 
false, "secret": false, "security": "insecure:ssl", "defaultValue": false, 
"configurationClass": 
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration", 
"configurationField": "configuration", "description": "If we want to trust all 
certificate [...]
     "uriEndpointOverride": { "index": 12, "kind": "parameter", "displayName": 
"Uri Endpoint Override", "group": "producer", "label": "", "required": false, 
"type": "string", "javaType": "java.lang.String", "deprecated": false, 
"autowired": false, "secret": false, "configurationClass": 
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration", 
"configurationField": "configuration", "description": "Set the overriding uri 
endpoint. This option needs to be used in combination wit [...]
     "useDefaultCredentialsProvider": { "index": 13, "kind": "parameter", 
"displayName": "Use Default Credentials Provider", "group": "producer", 
"label": "", "required": false, "type": "boolean", "javaType": "boolean", 
"deprecated": false, "autowired": false, "secret": false, "defaultValue": 
false, "configurationClass": 
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration", 
"configurationField": "configuration", "description": "Set whether the 
Transcribe client should exp [...]
     "useProfileCredentialsProvider": { "index": 14, "kind": "parameter", 
"displayName": "Use Profile Credentials Provider", "group": "producer", 
"label": "", "required": false, "type": "boolean", "javaType": "boolean", 
"deprecated": false, "autowired": false, "secret": false, "defaultValue": 
false, "configurationClass": 
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration", 
"configurationField": "configuration", "description": "Set whether the 
Transcribe client should exp [...]
diff --git 
a/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/components/mongodb.json
 
b/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/components/mongodb.json
index 0118ae0c8885..0ba1c9451ab4 100644
--- 
a/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/components/mongodb.json
+++ 
b/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/components/mongodb.json
@@ -116,7 +116,7 @@
     "password": { "index": 54, "kind": "parameter", "displayName": "Password", 
"group": "security", "label": "security", "required": false, "type": "string", 
"javaType": "java.lang.String", "deprecated": false, "autowired": false, 
"secret": true, "security": "secret", "description": "User password for mongodb 
connection" },
     "sslContextParameters": { "index": 55, "kind": "parameter", "displayName": 
"Ssl Context Parameters", "group": "security", "label": "security", "required": 
false, "type": "object", "javaType": 
"org.apache.camel.support.jsse.SSLContextParameters", "deprecated": false, 
"autowired": false, "secret": false, "description": "SSL configuration using a 
Camel SSLContextParameters object. When configured, TLS is automatically 
enabled on the connection." },
     "tls": { "index": 56, "kind": "parameter", "displayName": "Tls", "group": 
"security", "label": "security", "required": false, "type": "boolean", 
"javaType": "boolean", "deprecated": false, "autowired": false, "secret": 
false, "defaultValue": false, "description": "Specifies that all communication 
with MongoDB instances should use TLS. Supersedes the ssl option. Default: 
false" },
-    "tlsAllowInvalidHostnames": { "index": 57, "kind": "parameter", 
"displayName": "Tls Allow Invalid Hostnames", "group": "security", "label": 
"security", "required": false, "type": "boolean", "javaType": "boolean", 
"deprecated": false, "autowired": false, "secret": false, "defaultValue": 
false, "description": "Specifies that the driver should allow invalid hostnames 
in the certificate for TLS connections. Supersedes sslInvalidHostNameAllowed. 
Has the same effect as tlsInsecure by setti [...]
+    "tlsAllowInvalidHostnames": { "index": 57, "kind": "parameter", 
"displayName": "Tls Allow Invalid Hostnames", "group": "security", "label": 
"security", "required": false, "type": "boolean", "javaType": "boolean", 
"deprecated": false, "autowired": false, "secret": false, "security": 
"insecure:ssl", "defaultValue": false, "description": "Specifies that the 
driver should allow invalid hostnames in the certificate for TLS connections. 
Supersedes sslInvalidHostNameAllowed. Has the same ef [...]
     "username": { "index": 58, "kind": "parameter", "displayName": "Username", 
"group": "security", "label": "security", "required": false, "type": "string", 
"javaType": "java.lang.String", "deprecated": false, "autowired": false, 
"secret": true, "security": "secret", "description": "Username for mongodb 
connection" }
   }
 }
diff --git 
a/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/components/twitter-directmessage.json
 
b/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/components/twitter-directmessage.json
index 905b0d49c39c..9f0ae4be0f1f 100644
--- 
a/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/components/twitter-directmessage.json
+++ 
b/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/components/twitter-directmessage.json
@@ -31,7 +31,7 @@
     "healthCheckConsumerEnabled": { "index": 3, "kind": "property", 
"displayName": "Health Check Consumer Enabled", "group": "health", "label": 
"health", "required": false, "type": "boolean", "javaType": "boolean", 
"deprecated": false, "autowired": false, "secret": false, "defaultValue": true, 
"description": "Used for enabling or disabling all consumer based health checks 
from this component" },
     "healthCheckProducerEnabled": { "index": 4, "kind": "property", 
"displayName": "Health Check Producer Enabled", "group": "health", "label": 
"health", "required": false, "type": "boolean", "javaType": "boolean", 
"deprecated": false, "autowired": false, "secret": false, "defaultValue": true, 
"description": "Used for enabling or disabling all producer based health checks 
from this component. Notice: Camel has by default disabled all producer based 
health-checks. You can turn on producer [...]
     "httpProxyHost": { "index": 5, "kind": "property", "displayName": "Http 
Proxy Host", "group": "proxy", "label": "proxy", "required": false, "type": 
"string", "javaType": "java.lang.String", "deprecated": false, "autowired": 
false, "secret": false, "description": "The http proxy host which can be used 
for the camel-twitter." },
-    "httpProxyPassword": { "index": 6, "kind": "property", "displayName": 
"Http Proxy Password", "group": "proxy", "label": "proxy", "required": false, 
"type": "string", "javaType": "java.lang.String", "deprecated": false, 
"autowired": false, "secret": false, "description": "The http proxy password 
which can be used for the camel-twitter." },
+    "httpProxyPassword": { "index": 6, "kind": "property", "displayName": 
"Http Proxy Password", "group": "proxy", "label": "proxy", "required": false, 
"type": "string", "javaType": "java.lang.String", "deprecated": false, 
"autowired": false, "secret": true, "security": "secret", "description": "The 
http proxy password which can be used for the camel-twitter." },
     "httpProxyPort": { "index": 7, "kind": "property", "displayName": "Http 
Proxy Port", "group": "proxy", "label": "proxy", "required": false, "type": 
"integer", "javaType": "int", "deprecated": false, "autowired": false, 
"secret": false, "description": "The http proxy port which can be used for the 
camel-twitter." },
     "httpProxyUser": { "index": 8, "kind": "property", "displayName": "Http 
Proxy User", "group": "proxy", "label": "proxy", "required": false, "type": 
"string", "javaType": "java.lang.String", "deprecated": false, "autowired": 
false, "secret": false, "description": "The http proxy user which can be used 
for the camel-twitter." },
     "accessToken": { "index": 9, "kind": "property", "displayName": "Access 
Token", "group": "security", "label": "security", "required": false, "type": 
"string", "javaType": "java.lang.String", "deprecated": false, "autowired": 
false, "secret": true, "security": "secret", "description": "The access token" 
},
diff --git 
a/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/components/twitter-search.json
 
b/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/components/twitter-search.json
index 346e50896a23..7b828c775f4c 100644
--- 
a/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/components/twitter-search.json
+++ 
b/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/components/twitter-search.json
@@ -31,7 +31,7 @@
     "healthCheckConsumerEnabled": { "index": 3, "kind": "property", 
"displayName": "Health Check Consumer Enabled", "group": "health", "label": 
"health", "required": false, "type": "boolean", "javaType": "boolean", 
"deprecated": false, "autowired": false, "secret": false, "defaultValue": true, 
"description": "Used for enabling or disabling all consumer based health checks 
from this component" },
     "healthCheckProducerEnabled": { "index": 4, "kind": "property", 
"displayName": "Health Check Producer Enabled", "group": "health", "label": 
"health", "required": false, "type": "boolean", "javaType": "boolean", 
"deprecated": false, "autowired": false, "secret": false, "defaultValue": true, 
"description": "Used for enabling or disabling all producer based health checks 
from this component. Notice: Camel has by default disabled all producer based 
health-checks. You can turn on producer [...]
     "httpProxyHost": { "index": 5, "kind": "property", "displayName": "Http 
Proxy Host", "group": "proxy", "label": "proxy", "required": false, "type": 
"string", "javaType": "java.lang.String", "deprecated": false, "autowired": 
false, "secret": false, "description": "The http proxy host which can be used 
for the camel-twitter." },
-    "httpProxyPassword": { "index": 6, "kind": "property", "displayName": 
"Http Proxy Password", "group": "proxy", "label": "proxy", "required": false, 
"type": "string", "javaType": "java.lang.String", "deprecated": false, 
"autowired": false, "secret": false, "description": "The http proxy password 
which can be used for the camel-twitter." },
+    "httpProxyPassword": { "index": 6, "kind": "property", "displayName": 
"Http Proxy Password", "group": "proxy", "label": "proxy", "required": false, 
"type": "string", "javaType": "java.lang.String", "deprecated": false, 
"autowired": false, "secret": true, "security": "secret", "description": "The 
http proxy password which can be used for the camel-twitter." },
     "httpProxyPort": { "index": 7, "kind": "property", "displayName": "Http 
Proxy Port", "group": "proxy", "label": "proxy", "required": false, "type": 
"integer", "javaType": "int", "deprecated": false, "autowired": false, 
"secret": false, "description": "The http proxy port which can be used for the 
camel-twitter." },
     "httpProxyUser": { "index": 8, "kind": "property", "displayName": "Http 
Proxy User", "group": "proxy", "label": "proxy", "required": false, "type": 
"string", "javaType": "java.lang.String", "deprecated": false, "autowired": 
false, "secret": false, "description": "The http proxy user which can be used 
for the camel-twitter." },
     "accessToken": { "index": 9, "kind": "property", "displayName": "Access 
Token", "group": "security", "label": "security", "required": false, "type": 
"string", "javaType": "java.lang.String", "deprecated": false, "autowired": 
false, "secret": true, "security": "secret", "description": "The access token" 
},
diff --git 
a/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/components/twitter-timeline.json
 
b/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/components/twitter-timeline.json
index d85cb6f8e83e..4b633cda9130 100644
--- 
a/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/components/twitter-timeline.json
+++ 
b/catalog/camel-catalog/src/generated/resources/org/apache/camel/catalog/components/twitter-timeline.json
@@ -31,7 +31,7 @@
     "healthCheckConsumerEnabled": { "index": 3, "kind": "property", 
"displayName": "Health Check Consumer Enabled", "group": "health", "label": 
"health", "required": false, "type": "boolean", "javaType": "boolean", 
"deprecated": false, "autowired": false, "secret": false, "defaultValue": true, 
"description": "Used for enabling or disabling all consumer based health checks 
from this component" },
     "healthCheckProducerEnabled": { "index": 4, "kind": "property", 
"displayName": "Health Check Producer Enabled", "group": "health", "label": 
"health", "required": false, "type": "boolean", "javaType": "boolean", 
"deprecated": false, "autowired": false, "secret": false, "defaultValue": true, 
"description": "Used for enabling or disabling all producer based health checks 
from this component. Notice: Camel has by default disabled all producer based 
health-checks. You can turn on producer [...]
     "httpProxyHost": { "index": 5, "kind": "property", "displayName": "Http 
Proxy Host", "group": "proxy", "label": "proxy", "required": false, "type": 
"string", "javaType": "java.lang.String", "deprecated": false, "autowired": 
false, "secret": false, "description": "The http proxy host which can be used 
for the camel-twitter." },
-    "httpProxyPassword": { "index": 6, "kind": "property", "displayName": 
"Http Proxy Password", "group": "proxy", "label": "proxy", "required": false, 
"type": "string", "javaType": "java.lang.String", "deprecated": false, 
"autowired": false, "secret": false, "description": "The http proxy password 
which can be used for the camel-twitter." },
+    "httpProxyPassword": { "index": 6, "kind": "property", "displayName": 
"Http Proxy Password", "group": "proxy", "label": "proxy", "required": false, 
"type": "string", "javaType": "java.lang.String", "deprecated": false, 
"autowired": false, "secret": true, "security": "secret", "description": "The 
http proxy password which can be used for the camel-twitter." },
     "httpProxyPort": { "index": 7, "kind": "property", "displayName": "Http 
Proxy Port", "group": "proxy", "label": "proxy", "required": false, "type": 
"integer", "javaType": "int", "deprecated": false, "autowired": false, 
"secret": false, "description": "The http proxy port which can be used for the 
camel-twitter." },
     "httpProxyUser": { "index": 8, "kind": "property", "displayName": "Http 
Proxy User", "group": "proxy", "label": "proxy", "required": false, "type": 
"string", "javaType": "java.lang.String", "deprecated": false, "autowired": 
false, "secret": false, "description": "The http proxy user which can be used 
for the camel-twitter." },
     "accessToken": { "index": 9, "kind": "property", "displayName": "Access 
Token", "group": "security", "label": "security", "required": false, "type": 
"string", "javaType": "java.lang.String", "deprecated": false, "autowired": 
false, "secret": true, "security": "secret", "description": "The access token" 
},
diff --git 
a/components/camel-aws/camel-aws2-transcribe/src/generated/resources/META-INF/org/apache/camel/component/aws2/transcribe/aws2-transcribe.json
 
b/components/camel-aws/camel-aws2-transcribe/src/generated/resources/META-INF/org/apache/camel/component/aws2/transcribe/aws2-transcribe.json
index 4fb1f99f040d..46f984f20ada 100644
--- 
a/components/camel-aws/camel-aws2-transcribe/src/generated/resources/META-INF/org/apache/camel/component/aws2/transcribe/aws2-transcribe.json
+++ 
b/components/camel-aws/camel-aws2-transcribe/src/generated/resources/META-INF/org/apache/camel/component/aws2/transcribe/aws2-transcribe.json
@@ -36,7 +36,7 @@
     "proxyProtocol": { "index": 9, "kind": "property", "displayName": "Proxy 
Protocol", "group": "producer", "label": "", "required": false, "type": "enum", 
"javaType": "software.amazon.awssdk.core.Protocol", "enum": [ "HTTP", "HTTPS" 
], "deprecated": false, "autowired": false, "secret": false, "defaultValue": 
"HTTPS", "configurationClass": 
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration", 
"configurationField": "configuration", "description": "To define a proxy proto 
[...]
     "region": { "index": 10, "kind": "property", "displayName": "Region", 
"group": "producer", "label": "", "required": false, "type": "string", 
"javaType": "java.lang.String", "deprecated": false, "autowired": false, 
"secret": false, "configurationClass": 
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration", 
"configurationField": "configuration", "description": "The region in which 
Transcribe client needs to work. When using this parameter, the configuration 
will expect [...]
     "transcribeClient": { "index": 11, "kind": "property", "displayName": 
"Transcribe Client", "group": "producer", "label": "", "required": false, 
"type": "object", "javaType": 
"software.amazon.awssdk.services.transcribe.TranscribeClient", "deprecated": 
false, "autowired": false, "secret": false, "configurationClass": 
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration", 
"configurationField": "configuration", "description": "To use a existing 
configured AWS Transcribe a [...]
-    "trustAllCertificates": { "index": 12, "kind": "property", "displayName": 
"Trust All Certificates", "group": "producer", "label": "", "required": false, 
"type": "boolean", "javaType": "boolean", "deprecated": false, "autowired": 
false, "secret": false, "security": "insecure:ssl", "defaultValue": true, 
"configurationClass": 
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration", 
"configurationField": "configuration", "description": "If we want to trust all 
certificates  [...]
+    "trustAllCertificates": { "index": 12, "kind": "property", "displayName": 
"Trust All Certificates", "group": "producer", "label": "", "required": false, 
"type": "boolean", "javaType": "boolean", "deprecated": false, "autowired": 
false, "secret": false, "security": "insecure:ssl", "defaultValue": false, 
"configurationClass": 
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration", 
"configurationField": "configuration", "description": "If we want to trust all 
certificates [...]
     "uriEndpointOverride": { "index": 13, "kind": "property", "displayName": 
"Uri Endpoint Override", "group": "producer", "label": "", "required": false, 
"type": "string", "javaType": "java.lang.String", "deprecated": false, 
"autowired": false, "secret": false, "configurationClass": 
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration", 
"configurationField": "configuration", "description": "Set the overriding uri 
endpoint. This option needs to be used in combination with [...]
     "useDefaultCredentialsProvider": { "index": 14, "kind": "property", 
"displayName": "Use Default Credentials Provider", "group": "producer", 
"label": "", "required": false, "type": "boolean", "javaType": "boolean", 
"deprecated": false, "autowired": false, "secret": false, "defaultValue": 
false, "configurationClass": 
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration", 
"configurationField": "configuration", "description": "Set whether the 
Transcribe client should expe [...]
     "useProfileCredentialsProvider": { "index": 15, "kind": "property", 
"displayName": "Use Profile Credentials Provider", "group": "producer", 
"label": "", "required": false, "type": "boolean", "javaType": "boolean", 
"deprecated": false, "autowired": false, "secret": false, "defaultValue": 
false, "configurationClass": 
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration", 
"configurationField": "configuration", "description": "Set whether the 
Transcribe client should expe [...]
@@ -85,7 +85,7 @@
     "proxyProtocol": { "index": 8, "kind": "parameter", "displayName": "Proxy 
Protocol", "group": "producer", "label": "", "required": false, "type": "enum", 
"javaType": "software.amazon.awssdk.core.Protocol", "enum": [ "HTTP", "HTTPS" 
], "deprecated": false, "autowired": false, "secret": false, "defaultValue": 
"HTTPS", "configurationClass": 
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration", 
"configurationField": "configuration", "description": "To define a proxy prot 
[...]
     "region": { "index": 9, "kind": "parameter", "displayName": "Region", 
"group": "producer", "label": "", "required": false, "type": "string", 
"javaType": "java.lang.String", "deprecated": false, "autowired": false, 
"secret": false, "configurationClass": 
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration", 
"configurationField": "configuration", "description": "The region in which 
Transcribe client needs to work. When using this parameter, the configuration 
will expect [...]
     "transcribeClient": { "index": 10, "kind": "parameter", "displayName": 
"Transcribe Client", "group": "producer", "label": "", "required": false, 
"type": "object", "javaType": 
"software.amazon.awssdk.services.transcribe.TranscribeClient", "deprecated": 
false, "autowired": false, "secret": false, "configurationClass": 
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration", 
"configurationField": "configuration", "description": "To use a existing 
configured AWS Transcribe  [...]
-    "trustAllCertificates": { "index": 11, "kind": "parameter", "displayName": 
"Trust All Certificates", "group": "producer", "label": "", "required": false, 
"type": "boolean", "javaType": "boolean", "deprecated": false, "autowired": 
false, "secret": false, "security": "insecure:ssl", "defaultValue": true, 
"configurationClass": 
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration", 
"configurationField": "configuration", "description": "If we want to trust all 
certificates [...]
+    "trustAllCertificates": { "index": 11, "kind": "parameter", "displayName": 
"Trust All Certificates", "group": "producer", "label": "", "required": false, 
"type": "boolean", "javaType": "boolean", "deprecated": false, "autowired": 
false, "secret": false, "security": "insecure:ssl", "defaultValue": false, 
"configurationClass": 
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration", 
"configurationField": "configuration", "description": "If we want to trust all 
certificate [...]
     "uriEndpointOverride": { "index": 12, "kind": "parameter", "displayName": 
"Uri Endpoint Override", "group": "producer", "label": "", "required": false, 
"type": "string", "javaType": "java.lang.String", "deprecated": false, 
"autowired": false, "secret": false, "configurationClass": 
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration", 
"configurationField": "configuration", "description": "Set the overriding uri 
endpoint. This option needs to be used in combination wit [...]
     "useDefaultCredentialsProvider": { "index": 13, "kind": "parameter", 
"displayName": "Use Default Credentials Provider", "group": "producer", 
"label": "", "required": false, "type": "boolean", "javaType": "boolean", 
"deprecated": false, "autowired": false, "secret": false, "defaultValue": 
false, "configurationClass": 
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration", 
"configurationField": "configuration", "description": "Set whether the 
Transcribe client should exp [...]
     "useProfileCredentialsProvider": { "index": 14, "kind": "parameter", 
"displayName": "Use Profile Credentials Provider", "group": "producer", 
"label": "", "required": false, "type": "boolean", "javaType": "boolean", 
"deprecated": false, "autowired": false, "secret": false, "defaultValue": 
false, "configurationClass": 
"org.apache.camel.component.aws2.transcribe.Transcribe2Configuration", 
"configurationField": "configuration", "description": "Set whether the 
Transcribe client should exp [...]
diff --git 
a/components/camel-aws/camel-aws2-transcribe/src/main/java/org/apache/camel/component/aws2/transcribe/Transcribe2Configuration.java
 
b/components/camel-aws/camel-aws2-transcribe/src/main/java/org/apache/camel/component/aws2/transcribe/Transcribe2Configuration.java
index 9bee49097a92..1125854fd3bc 100644
--- 
a/components/camel-aws/camel-aws2-transcribe/src/main/java/org/apache/camel/component/aws2/transcribe/Transcribe2Configuration.java
+++ 
b/components/camel-aws/camel-aws2-transcribe/src/main/java/org/apache/camel/component/aws2/transcribe/Transcribe2Configuration.java
@@ -45,7 +45,7 @@ public class Transcribe2Configuration implements Cloneable, 
AwsCommonConfigurati
     private boolean overrideEndpoint;
     @UriParam
     private String uriEndpointOverride;
-    @UriParam(security = "insecure:ssl", defaultValue = "true")
+    @UriParam(security = "insecure:ssl", defaultValue = "false")
     private boolean trustAllCertificates;
     @UriParam(defaultValue = "false")
     private boolean useDefaultCredentialsProvider;
diff --git 
a/components/camel-mongodb/src/generated/resources/META-INF/org/apache/camel/component/mongodb/mongodb.json
 
b/components/camel-mongodb/src/generated/resources/META-INF/org/apache/camel/component/mongodb/mongodb.json
index 0118ae0c8885..0ba1c9451ab4 100644
--- 
a/components/camel-mongodb/src/generated/resources/META-INF/org/apache/camel/component/mongodb/mongodb.json
+++ 
b/components/camel-mongodb/src/generated/resources/META-INF/org/apache/camel/component/mongodb/mongodb.json
@@ -116,7 +116,7 @@
     "password": { "index": 54, "kind": "parameter", "displayName": "Password", 
"group": "security", "label": "security", "required": false, "type": "string", 
"javaType": "java.lang.String", "deprecated": false, "autowired": false, 
"secret": true, "security": "secret", "description": "User password for mongodb 
connection" },
     "sslContextParameters": { "index": 55, "kind": "parameter", "displayName": 
"Ssl Context Parameters", "group": "security", "label": "security", "required": 
false, "type": "object", "javaType": 
"org.apache.camel.support.jsse.SSLContextParameters", "deprecated": false, 
"autowired": false, "secret": false, "description": "SSL configuration using a 
Camel SSLContextParameters object. When configured, TLS is automatically 
enabled on the connection." },
     "tls": { "index": 56, "kind": "parameter", "displayName": "Tls", "group": 
"security", "label": "security", "required": false, "type": "boolean", 
"javaType": "boolean", "deprecated": false, "autowired": false, "secret": 
false, "defaultValue": false, "description": "Specifies that all communication 
with MongoDB instances should use TLS. Supersedes the ssl option. Default: 
false" },
-    "tlsAllowInvalidHostnames": { "index": 57, "kind": "parameter", 
"displayName": "Tls Allow Invalid Hostnames", "group": "security", "label": 
"security", "required": false, "type": "boolean", "javaType": "boolean", 
"deprecated": false, "autowired": false, "secret": false, "defaultValue": 
false, "description": "Specifies that the driver should allow invalid hostnames 
in the certificate for TLS connections. Supersedes sslInvalidHostNameAllowed. 
Has the same effect as tlsInsecure by setti [...]
+    "tlsAllowInvalidHostnames": { "index": 57, "kind": "parameter", 
"displayName": "Tls Allow Invalid Hostnames", "group": "security", "label": 
"security", "required": false, "type": "boolean", "javaType": "boolean", 
"deprecated": false, "autowired": false, "secret": false, "security": 
"insecure:ssl", "defaultValue": false, "description": "Specifies that the 
driver should allow invalid hostnames in the certificate for TLS connections. 
Supersedes sslInvalidHostNameAllowed. Has the same ef [...]
     "username": { "index": 58, "kind": "parameter", "displayName": "Username", 
"group": "security", "label": "security", "required": false, "type": "string", 
"javaType": "java.lang.String", "deprecated": false, "autowired": false, 
"secret": true, "security": "secret", "description": "Username for mongodb 
connection" }
   }
 }
diff --git 
a/components/camel-mongodb/src/main/java/org/apache/camel/component/mongodb/MongoDbEndpoint.java
 
b/components/camel-mongodb/src/main/java/org/apache/camel/component/mongodb/MongoDbEndpoint.java
index 97949cd2eb88..774d095c2b9b 100644
--- 
a/components/camel-mongodb/src/main/java/org/apache/camel/component/mongodb/MongoDbEndpoint.java
+++ 
b/components/camel-mongodb/src/main/java/org/apache/camel/component/mongodb/MongoDbEndpoint.java
@@ -139,7 +139,7 @@ public class MongoDbEndpoint extends DefaultEndpoint 
implements EndpointServiceL
     //Connection Configuration
     @UriParam(label = "security", defaultValue = "false")
     private boolean tls;
-    @UriParam(label = "security", defaultValue = "false")
+    @UriParam(label = "security", defaultValue = "false", security = 
"insecure:ssl")
     private boolean tlsAllowInvalidHostnames;
     @UriParam(label = "security")
     private SSLContextParameters sslContextParameters;
diff --git 
a/components/camel-twitter/src/generated/resources/META-INF/org/apache/camel/component/twitter/directmessage/twitter-directmessage.json
 
b/components/camel-twitter/src/generated/resources/META-INF/org/apache/camel/component/twitter/directmessage/twitter-directmessage.json
index 905b0d49c39c..9f0ae4be0f1f 100644
--- 
a/components/camel-twitter/src/generated/resources/META-INF/org/apache/camel/component/twitter/directmessage/twitter-directmessage.json
+++ 
b/components/camel-twitter/src/generated/resources/META-INF/org/apache/camel/component/twitter/directmessage/twitter-directmessage.json
@@ -31,7 +31,7 @@
     "healthCheckConsumerEnabled": { "index": 3, "kind": "property", 
"displayName": "Health Check Consumer Enabled", "group": "health", "label": 
"health", "required": false, "type": "boolean", "javaType": "boolean", 
"deprecated": false, "autowired": false, "secret": false, "defaultValue": true, 
"description": "Used for enabling or disabling all consumer based health checks 
from this component" },
     "healthCheckProducerEnabled": { "index": 4, "kind": "property", 
"displayName": "Health Check Producer Enabled", "group": "health", "label": 
"health", "required": false, "type": "boolean", "javaType": "boolean", 
"deprecated": false, "autowired": false, "secret": false, "defaultValue": true, 
"description": "Used for enabling or disabling all producer based health checks 
from this component. Notice: Camel has by default disabled all producer based 
health-checks. You can turn on producer [...]
     "httpProxyHost": { "index": 5, "kind": "property", "displayName": "Http 
Proxy Host", "group": "proxy", "label": "proxy", "required": false, "type": 
"string", "javaType": "java.lang.String", "deprecated": false, "autowired": 
false, "secret": false, "description": "The http proxy host which can be used 
for the camel-twitter." },
-    "httpProxyPassword": { "index": 6, "kind": "property", "displayName": 
"Http Proxy Password", "group": "proxy", "label": "proxy", "required": false, 
"type": "string", "javaType": "java.lang.String", "deprecated": false, 
"autowired": false, "secret": false, "description": "The http proxy password 
which can be used for the camel-twitter." },
+    "httpProxyPassword": { "index": 6, "kind": "property", "displayName": 
"Http Proxy Password", "group": "proxy", "label": "proxy", "required": false, 
"type": "string", "javaType": "java.lang.String", "deprecated": false, 
"autowired": false, "secret": true, "security": "secret", "description": "The 
http proxy password which can be used for the camel-twitter." },
     "httpProxyPort": { "index": 7, "kind": "property", "displayName": "Http 
Proxy Port", "group": "proxy", "label": "proxy", "required": false, "type": 
"integer", "javaType": "int", "deprecated": false, "autowired": false, 
"secret": false, "description": "The http proxy port which can be used for the 
camel-twitter." },
     "httpProxyUser": { "index": 8, "kind": "property", "displayName": "Http 
Proxy User", "group": "proxy", "label": "proxy", "required": false, "type": 
"string", "javaType": "java.lang.String", "deprecated": false, "autowired": 
false, "secret": false, "description": "The http proxy user which can be used 
for the camel-twitter." },
     "accessToken": { "index": 9, "kind": "property", "displayName": "Access 
Token", "group": "security", "label": "security", "required": false, "type": 
"string", "javaType": "java.lang.String", "deprecated": false, "autowired": 
false, "secret": true, "security": "secret", "description": "The access token" 
},
diff --git 
a/components/camel-twitter/src/generated/resources/META-INF/org/apache/camel/component/twitter/search/twitter-search.json
 
b/components/camel-twitter/src/generated/resources/META-INF/org/apache/camel/component/twitter/search/twitter-search.json
index 346e50896a23..7b828c775f4c 100644
--- 
a/components/camel-twitter/src/generated/resources/META-INF/org/apache/camel/component/twitter/search/twitter-search.json
+++ 
b/components/camel-twitter/src/generated/resources/META-INF/org/apache/camel/component/twitter/search/twitter-search.json
@@ -31,7 +31,7 @@
     "healthCheckConsumerEnabled": { "index": 3, "kind": "property", 
"displayName": "Health Check Consumer Enabled", "group": "health", "label": 
"health", "required": false, "type": "boolean", "javaType": "boolean", 
"deprecated": false, "autowired": false, "secret": false, "defaultValue": true, 
"description": "Used for enabling or disabling all consumer based health checks 
from this component" },
     "healthCheckProducerEnabled": { "index": 4, "kind": "property", 
"displayName": "Health Check Producer Enabled", "group": "health", "label": 
"health", "required": false, "type": "boolean", "javaType": "boolean", 
"deprecated": false, "autowired": false, "secret": false, "defaultValue": true, 
"description": "Used for enabling or disabling all producer based health checks 
from this component. Notice: Camel has by default disabled all producer based 
health-checks. You can turn on producer [...]
     "httpProxyHost": { "index": 5, "kind": "property", "displayName": "Http 
Proxy Host", "group": "proxy", "label": "proxy", "required": false, "type": 
"string", "javaType": "java.lang.String", "deprecated": false, "autowired": 
false, "secret": false, "description": "The http proxy host which can be used 
for the camel-twitter." },
-    "httpProxyPassword": { "index": 6, "kind": "property", "displayName": 
"Http Proxy Password", "group": "proxy", "label": "proxy", "required": false, 
"type": "string", "javaType": "java.lang.String", "deprecated": false, 
"autowired": false, "secret": false, "description": "The http proxy password 
which can be used for the camel-twitter." },
+    "httpProxyPassword": { "index": 6, "kind": "property", "displayName": 
"Http Proxy Password", "group": "proxy", "label": "proxy", "required": false, 
"type": "string", "javaType": "java.lang.String", "deprecated": false, 
"autowired": false, "secret": true, "security": "secret", "description": "The 
http proxy password which can be used for the camel-twitter." },
     "httpProxyPort": { "index": 7, "kind": "property", "displayName": "Http 
Proxy Port", "group": "proxy", "label": "proxy", "required": false, "type": 
"integer", "javaType": "int", "deprecated": false, "autowired": false, 
"secret": false, "description": "The http proxy port which can be used for the 
camel-twitter." },
     "httpProxyUser": { "index": 8, "kind": "property", "displayName": "Http 
Proxy User", "group": "proxy", "label": "proxy", "required": false, "type": 
"string", "javaType": "java.lang.String", "deprecated": false, "autowired": 
false, "secret": false, "description": "The http proxy user which can be used 
for the camel-twitter." },
     "accessToken": { "index": 9, "kind": "property", "displayName": "Access 
Token", "group": "security", "label": "security", "required": false, "type": 
"string", "javaType": "java.lang.String", "deprecated": false, "autowired": 
false, "secret": true, "security": "secret", "description": "The access token" 
},
diff --git 
a/components/camel-twitter/src/generated/resources/META-INF/org/apache/camel/component/twitter/timeline/twitter-timeline.json
 
b/components/camel-twitter/src/generated/resources/META-INF/org/apache/camel/component/twitter/timeline/twitter-timeline.json
index d85cb6f8e83e..4b633cda9130 100644
--- 
a/components/camel-twitter/src/generated/resources/META-INF/org/apache/camel/component/twitter/timeline/twitter-timeline.json
+++ 
b/components/camel-twitter/src/generated/resources/META-INF/org/apache/camel/component/twitter/timeline/twitter-timeline.json
@@ -31,7 +31,7 @@
     "healthCheckConsumerEnabled": { "index": 3, "kind": "property", 
"displayName": "Health Check Consumer Enabled", "group": "health", "label": 
"health", "required": false, "type": "boolean", "javaType": "boolean", 
"deprecated": false, "autowired": false, "secret": false, "defaultValue": true, 
"description": "Used for enabling or disabling all consumer based health checks 
from this component" },
     "healthCheckProducerEnabled": { "index": 4, "kind": "property", 
"displayName": "Health Check Producer Enabled", "group": "health", "label": 
"health", "required": false, "type": "boolean", "javaType": "boolean", 
"deprecated": false, "autowired": false, "secret": false, "defaultValue": true, 
"description": "Used for enabling or disabling all producer based health checks 
from this component. Notice: Camel has by default disabled all producer based 
health-checks. You can turn on producer [...]
     "httpProxyHost": { "index": 5, "kind": "property", "displayName": "Http 
Proxy Host", "group": "proxy", "label": "proxy", "required": false, "type": 
"string", "javaType": "java.lang.String", "deprecated": false, "autowired": 
false, "secret": false, "description": "The http proxy host which can be used 
for the camel-twitter." },
-    "httpProxyPassword": { "index": 6, "kind": "property", "displayName": 
"Http Proxy Password", "group": "proxy", "label": "proxy", "required": false, 
"type": "string", "javaType": "java.lang.String", "deprecated": false, 
"autowired": false, "secret": false, "description": "The http proxy password 
which can be used for the camel-twitter." },
+    "httpProxyPassword": { "index": 6, "kind": "property", "displayName": 
"Http Proxy Password", "group": "proxy", "label": "proxy", "required": false, 
"type": "string", "javaType": "java.lang.String", "deprecated": false, 
"autowired": false, "secret": true, "security": "secret", "description": "The 
http proxy password which can be used for the camel-twitter." },
     "httpProxyPort": { "index": 7, "kind": "property", "displayName": "Http 
Proxy Port", "group": "proxy", "label": "proxy", "required": false, "type": 
"integer", "javaType": "int", "deprecated": false, "autowired": false, 
"secret": false, "description": "The http proxy port which can be used for the 
camel-twitter." },
     "httpProxyUser": { "index": 8, "kind": "property", "displayName": "Http 
Proxy User", "group": "proxy", "label": "proxy", "required": false, "type": 
"string", "javaType": "java.lang.String", "deprecated": false, "autowired": 
false, "secret": false, "description": "The http proxy user which can be used 
for the camel-twitter." },
     "accessToken": { "index": 9, "kind": "property", "displayName": "Access 
Token", "group": "security", "label": "security", "required": false, "type": 
"string", "javaType": "java.lang.String", "deprecated": false, "autowired": 
false, "secret": true, "security": "secret", "description": "The access token" 
},
diff --git 
a/components/camel-twitter/src/main/java/org/apache/camel/component/twitter/AbstractTwitterComponent.java
 
b/components/camel-twitter/src/main/java/org/apache/camel/component/twitter/AbstractTwitterComponent.java
index 443ef3c872bd..09bdec01f4f9 100644
--- 
a/components/camel-twitter/src/main/java/org/apache/camel/component/twitter/AbstractTwitterComponent.java
+++ 
b/components/camel-twitter/src/main/java/org/apache/camel/component/twitter/AbstractTwitterComponent.java
@@ -39,7 +39,7 @@ public abstract class AbstractTwitterComponent extends 
HealthCheckComponent {
     private String httpProxyHost;
     @Metadata(label = "proxy")
     private String httpProxyUser;
-    @Metadata(label = "proxy")
+    @Metadata(label = "proxy", security = "secret")
     private String httpProxyPassword;
     @Metadata(label = "proxy")
     private Integer httpProxyPort;
diff --git 
a/core/camel-util/src/main/java/org/apache/camel/util/SecurityUtils.java 
b/core/camel-util/src/main/java/org/apache/camel/util/SecurityUtils.java
index 7019fd2c1801..be1f32cf6e28 100644
--- a/core/camel-util/src/main/java/org/apache/camel/util/SecurityUtils.java
+++ b/core/camel-util/src/main/java/org/apache/camel/util/SecurityUtils.java
@@ -91,6 +91,7 @@ public final class SecurityUtils {
         map.put("sslendpointalgorithm", new SecurityOption(INSECURE_SSL, 
"none"));
         map.put("stricthostkeychecking", new SecurityOption(INSECURE_SSL, ""));
         map.put("tls", new SecurityOption(INSECURE_SSL, VALUE_FALSE));
+        map.put("tlsallowinvalidhostnames", new SecurityOption(INSECURE_SSL, 
"true"));
         map.put("transferexception", new 
SecurityOption(INSECURE_SERIALIZATION, "true"));
         map.put("transferexchange", new SecurityOption(INSECURE_SERIALIZATION, 
"true"));
         map.put("trustallcertificates", new SecurityOption(INSECURE_SSL, 
"true"));
@@ -203,6 +204,8 @@ public final class SecurityUtils {
                 "component:sftp"));
         owners.put("tls", Set.of(
                 "component:pinecone"));
+        owners.put("tlsallowinvalidhostnames", Set.of(
+                "component:mongodb"));
         owners.put("transferexception", Set.of(
                 "component:activemq",
                 "component:activemq6",
diff --git 
a/core/camel-util/src/test/java/org/apache/camel/util/SecurityUtilsTest.java 
b/core/camel-util/src/test/java/org/apache/camel/util/SecurityUtilsTest.java
index ce1f1816ccd9..02b06367ee21 100644
--- a/core/camel-util/src/test/java/org/apache/camel/util/SecurityUtilsTest.java
+++ b/core/camel-util/src/test/java/org/apache/camel/util/SecurityUtilsTest.java
@@ -48,6 +48,16 @@ class SecurityUtilsTest {
         assertEquals("true", options.get("acceptanyspiffeid").insecureValue());
     }
 
+    @Test
+    void testHostnameVerificationOptionsAreRegistered() {
+        // every option that turns off TLS hostname verification must reach 
this map, otherwise
+        // camel.main.profile=prod cannot refuse it (CAMEL-25409)
+        
assertTrue(SecurityUtils.isInsecureValue("camel.component.mongodb.tlsAllowInvalidHostnames",
 true));
+        
assertFalse(SecurityUtils.isInsecureValue("camel.component.mongodb.tlsAllowInvalidHostnames",
 false));
+        
assertTrue(SecurityUtils.isInsecureValue("camel.component.netty-http.hostnameVerification",
 false));
+        
assertTrue(SecurityUtils.isInsecureValue("camel.component.splunk-hec.skipTlsVerify",
 true));
+    }
+
     @Test
     void testIsPlainTextSecret() {
         // plain text values should be detected
diff --git 
a/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_23.adoc 
b/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_23.adoc
index 380ef42e8968..d2523fd2258c 100644
--- a/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_23.adoc
+++ b/docs/user-manual/modules/ROOT/pages/camel-4x-upgrade-guide-4_23.adoc
@@ -1775,6 +1775,17 @@ This applies only to `camel-hivemq`: setting `ssl=false` 
on the other components
 policy check below. To keep `camel.component.hivemq.ssl = false` under a 
`fail` policy, list it in
 `camel.security.allowedProperties`.
 
+=== camel-mongodb
+
+The `tlsAllowInvalidHostnames` option is now marked `insecure:ssl`. The option 
turns off TLS hostname
+verification, so setting `camel.component.mongodb.tlsAllowInvalidHostnames = 
true` in the configuration is
+reported by the xref:security-policy.adoc[security policy] check: a warning by 
default, and a startup failure
+with the `prod` profile or `camel.security.insecureSslPolicy = fail`.
+
+Only the option of `camel-mongodb` is reported, see the `camel-main` section 
about the security policy check
+below. To keep `camel.component.mongodb.tlsAllowInvalidHostnames = true` under 
a `fail` policy, list it in
+`camel.security.allowedProperties`.
+
 === camel-main - security policy check matches component options by component
 
 The xref:security-policy.adoc[security policy] check matched an insecure 
option by its name only, so an
diff --git 
a/dsl/camel-componentdsl/src/generated/java/org/apache/camel/builder/component/dsl/Aws2TranscribeComponentBuilderFactory.java
 
b/dsl/camel-componentdsl/src/generated/java/org/apache/camel/builder/component/dsl/Aws2TranscribeComponentBuilderFactory.java
index a5df74ab294b..9c57807fb472 100644
--- 
a/dsl/camel-componentdsl/src/generated/java/org/apache/camel/builder/component/dsl/Aws2TranscribeComponentBuilderFactory.java
+++ 
b/dsl/camel-componentdsl/src/generated/java/org/apache/camel/builder/component/dsl/Aws2TranscribeComponentBuilderFactory.java
@@ -265,7 +265,7 @@ public interface Aws2TranscribeComponentBuilderFactory {
          * 
          * The option is a: &lt;code&gt;boolean&lt;/code&gt; type.
          * 
-         * Default: true
+         * Default: false
          * Group: producer
          * 
          * @param trustAllCertificates the value to set
diff --git 
a/dsl/camel-endpointdsl/src/generated/java/org/apache/camel/builder/endpoint/dsl/Transcribe2EndpointBuilderFactory.java
 
b/dsl/camel-endpointdsl/src/generated/java/org/apache/camel/builder/endpoint/dsl/Transcribe2EndpointBuilderFactory.java
index 1dfd0656a6be..656ad0618a2b 100644
--- 
a/dsl/camel-endpointdsl/src/generated/java/org/apache/camel/builder/endpoint/dsl/Transcribe2EndpointBuilderFactory.java
+++ 
b/dsl/camel-endpointdsl/src/generated/java/org/apache/camel/builder/endpoint/dsl/Transcribe2EndpointBuilderFactory.java
@@ -311,7 +311,7 @@ public interface Transcribe2EndpointBuilderFactory {
          * 
          * The option is a: <code>boolean</code> type.
          * 
-         * Default: true
+         * Default: false
          * Group: producer
          * 
          * @param trustAllCertificates the value to set
@@ -327,7 +327,7 @@ public interface Transcribe2EndpointBuilderFactory {
          * 
          * The option will be converted to a <code>boolean</code> type.
          * 
-         * Default: true
+         * Default: false
          * Group: producer
          * 
          * @param trustAllCertificates the value to set

Reply via email to