[ 
https://issues.apache.org/jira/browse/CAMEL-24291?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Andrea Cosentino resolved CAMEL-24291.
--------------------------------------
    Resolution: Fixed

Fixed on main via PR https://github.com/apache/camel/pull/25263. Main-only 
(4.22.0).

_Claude Code on behalf of Andrea Cosentino (@oscerd)._

> camel-jsch and camel-ssh: align host-key checking option metadata with 
> camel-ftp
> --------------------------------------------------------------------------------
>
>                 Key: CAMEL-24291
>                 URL: https://issues.apache.org/jira/browse/CAMEL-24291
>             Project: Camel
>          Issue Type: Improvement
>          Components: camel-jsch, camel-ssh
>            Reporter: Andrea Cosentino
>            Assignee: Andrea Cosentino
>            Priority: Minor
>             Fix For: 4.22.0
>
>
> CAMEL-23404 tagged the SFTP strictHostKeyChecking option with 
> security="insecure:ssl" so the production-profile policy has visibility of 
> it. The sibling SSH-based components were not brought in line:
> - camel-jsch (SCP): ScpConfiguration.strictHostKeyChecking is not tagged 
> security="insecure:ssl" (SFTP is). Separately, ScpComponent sets the JSch 
> global StrictHostKeyChecking=yes but ScpOperations.createSession() 
> unconditionally re-applies the per-session config value, so the 
> component-level global is always overridden - worth simplifying so the two 
> are not contradictory.
> - camel-ssh: SshConfiguration.knownHostsResource and failOnUnknownHost carry 
> no security="insecure:ssl" tag.
> Scope of this issue: add the insecure:ssl metadata tags for parity 
> (non-behavioural - regenerates catalog/docs) and tidy the SCP global/session 
> redundancy. Any change to the default values is a separate behavioural change 
> for a major release with an upgrade-guide entry.
> _Filed by Claude Code on behalf of Andrea Cosentino._



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to