[ 
https://issues.apache.org/jira/browse/CAMEL-24632?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18112332#comment-18112332
 ] 

Claus Ibsen commented on CAMEL-24632:
-------------------------------------

But yeah we should have used http as the default proxy scheme - they are on 
internal networks and usually trusted. https for proxy is rare.

> SSLException when GET/POST to https endpoint with proxy setting using 
> camel-http component
> ------------------------------------------------------------------------------------------
>
>                 Key: CAMEL-24632
>                 URL: https://issues.apache.org/jira/browse/CAMEL-24632
>             Project: Camel
>          Issue Type: Bug
>          Components: camel-http
>    Affects Versions: 4.18.4
>            Reporter: Xilai Dai
>            Priority: Minor
>
> With camel-http component calling a https endpoint with proxy setting:
> {code:java}
> from("timer:Timer_1?repeatCount=1).to("https://www.google.com/?proxyHost=yourProxyserver&proxyPort=yourProxyport";){code}
> It will end up with SSLException unexpectedly.
> {code:java}
> javax.net.ssl.SSLException: Unsupported or unrecognized SSL message   at 
> java.base/sun.security.ssl.SSLSocketInputRecord.handleUnknownRecord(SSLSocketInputRecord.java:462)
>    at 
> java.base/sun.security.ssl.SSLSocketInputRecord.decode(SSLSocketInputRecord.java:175)
>         at 
> java.base/sun.security.ssl.SSLTransport.decode(SSLTransport.java:111)        
> at java.base/sun.security.ssl.SSLSocketImpl.decode(SSLSocketImpl.java:1505)   
>   at 
> java.base/sun.security.ssl.SSLSocketImpl.readHandshakeRecord(SSLSocketImpl.java:1420)
>         at 
> java.base/sun.security.ssl.SSLSocketImpl.startHandshake(SSLSocketImpl.java:455)
>       at 
> java.base/sun.security.ssl.SSLSocketImpl.startHandshake(SSLSocketImpl.java:426)
>       at 
> org.apache.hc.client5.http.ssl.SSLConnectionSocketFactory.executeHandshake(SSLConnectionSocketFactory.java:303)
>       at 
> org.apache.hc.client5.http.ssl.SSLConnectionSocketFactory.createLayeredSocket(SSLConnectionSocketFactory.java:275)
>    at 
> org.apache.hc.client5.http.ssl.SSLConnectionSocketFactory.connectSocket(SSLConnectionSocketFactory.java:251)
>  at 
> org.apache.hc.client5.http.impl.io.DefaultHttpClientConnectionOperator.connect(DefaultHttpClientConnectionOperator.java:181)
>  at 
> org.apache.hc.client5.http.impl.io.PoolingHttpClientConnectionManager.connect(PoolingHttpClientConnectionManager.java:447)
>    at 
> org.apache.hc.client5.http.impl.classic.InternalExecRuntime.connectEndpoint(InternalExecRuntime.java:162)
>     at 
> org.apache.hc.client5.http.impl.classic.InternalExecRuntime.connectEndpoint(InternalExecRuntime.java:172)
>     at 
> org.apache.hc.client5.http.impl.classic.ConnectExec.execute(ConnectExec.java:146)
>     at 
> org.apache.hc.client5.http.impl.classic.ExecChainElement.execute(ExecChainElement.java:51)
>    at 
> org.apache.hc.client5.http.impl.classic.ProtocolExec.execute(ProtocolExec.java:192)
>   at 
> org.apache.hc.client5.http.impl.classic.ExecChainElement.execute(ExecChainElement.java:51)
>    at 
> org.apache.hc.client5.http.impl.classic.HttpRequestRetryExec.execute(HttpRequestRetryExec.java:96)
>    at 
> org.apache.hc.client5.http.impl.classic.ExecChainElement.execute(ExecChainElement.java:51)
>    at 
> org.apache.hc.client5.http.impl.classic.ContentCompressionExec.execute(ContentCompressionExec.java:152)
>       at 
> org.apache.hc.client5.http.impl.classic.ExecChainElement.execute(ExecChainElement.java:51)
>    at 
> org.apache.hc.client5.http.impl.classic.InternalHttpClient.doExecute(InternalHttpClient.java:170)
>     at 
> org.apache.hc.client5.http.impl.classic.CloseableHttpClient.execute(CloseableHttpClient.java:87)
>      at 
> org.apache.hc.client5.http.impl.classic.CloseableHttpClient.execute(CloseableHttpClient.java:55)
>      at 
> org.apache.hc.client5.http.classic.HttpClient.executeOpen(HttpClient.java:183)
>        at 
> org.apache.camel.component.http.HttpProducer.executeMethod(HttpProducer.java:485)
>     at 
> org.apache.camel.component.http.HttpProducer.process(HttpProducer.java:247) 
> {code}
> *Root cause:*
> There was a buddy method configureHttpProxy() in camel-http component (issue 
> existing on camel main branch)
> [https://github.com/apache/camel/blob/main/components/camel-http/src/main/java/org/apache/camel/component/http/HttpComponent.java#L380-L421]
>  
> "secure" here means "is the target endpoint https", that value is then used 
> to decide the scheme (http or https) for connecting to the proxy itself — 
> which is a completely different, unrelated thing.
> *Workaround:*
> proxyAuthScheme=http must be set explicitly when the target endpoint in 
> camel-http URI is https — otherwise Camel silently misconfigures the proxy 
> connection scheme.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to