[
https://issues.apache.org/jira/browse/CAMEL-24430?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Work on CAMEL-24430 started by Andrea Cosentino.
------------------------------------------------
> camel-as2 - signature verification and MIC comparison are not enforced on
> received messages and MDN receipts
> ------------------------------------------------------------------------------------------------------------
>
> Key: CAMEL-24430
> URL: https://issues.apache.org/jira/browse/CAMEL-24430
> Project: Camel
> Issue Type: Improvement
> Components: camel-as2
> Reporter: Andrea Cosentino
> Assignee: Andrea Cosentino
> Priority: Major
> Fix For: 4.23.0
>
>
> Two related gaps in how AS2 authenticity is established.
> *Inbound messages.* AS2Configuration.signatureVerificationRequired has no
> initialiser, so it defaults to false:
> {code:java}
> @UriParam(label = "security")
> private boolean signatureVerificationRequired;
> {code}
> and HttpMessageUtils documents the consequence itself: the unverified payload
> is delivered after logging a warning unless the flag is set. A component that
> accepts signed messages and can verify them arguably should not deliver
> unverified content by default.
> *MDN receipts.* On the client side AS2ClientManager.sendRequest() parses the
> response and returns:
> {code:java}
> response = as2ClientConnection.send(request, httpContext);
> EntityParser.parseAS2MessageEntity(response);
> {code}
> There is no signature verification of the receipt and no comparison of its
> Received-Content-MIC against the MIC of the content that was sent. grep
> across camel-as2-api shows RECEIVED_CONTENT_MIC only being parsed
> (DispositionNotificationContentUtils) and generated
> (AS2MessageDispositionNotificationEntity) - never compared. An MDN is the
> non-repudiation record for the interchange, so a receipt that is not verified
> does not carry the property it exists for.
> Proposal: verify the MDN signature against the configured/pinned partner
> chain and compare Received-Content-MIC with the locally computed MIC,
> surfacing the outcome to the route; and flip signatureVerificationRequired to
> true with an upgrade-guide entry, or refuse to start a consumer configured
> with a validation chain but with the flag off. The default change is
> breaking, so it needs the guide entry and may be main-only.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)