[
https://issues.apache.org/jira/browse/CAMEL-24474?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18112385#comment-18112385
]
Claus Ibsen commented on CAMEL-24474:
-------------------------------------
Fixed in https://github.com/apache/camel/pull/26164
> camel-as2 - support TLS delivery of asynchronous MDNs via SSLContextParameters
> ------------------------------------------------------------------------------
>
> Key: CAMEL-24474
> URL: https://issues.apache.org/jira/browse/CAMEL-24474
> Project: Camel
> Issue Type: Improvement
> Components: camel-as2
> Reporter: Andrea Cosentino
> Assignee: Andrea Cosentino
> Priority: Minor
> Fix For: 4.23.0
>
>
> The AS2 server can deliver an asynchronous MDN to the address named by the
> {{Receipt-Delivery-Option}} header of the received AS2 message.
> {{AS2AsynchronousMDNManager}} performs that delivery over a plain
> {{java.net.Socket}} and has no TLS support of any kind - there is no
> {{SSLContext}} or {{SSLSocket}} anywhere in the class.
> As a consequence an {{https}} delivery address has never actually been
> delivered over TLS. With an explicit port the request was written in
> cleartext to the TLS port and the peer reset the connection; without one it
> failed on {{new Socket(host, -1)}}. CAMEL-24417 therefore made the manager
> refuse a non-{{http}} delivery address outright rather than attempt it, and
> the 4.23 upgrade guide states that TLS delivery of asynchronous MDNs is
> unsupported.
> This issue tracks actually implementing it. The AS2 endpoint already exposes
> {{sslContextParameters}} for the client side, so the natural shape is:
> * build an {{SSLSocketFactory}} from the endpoint's {{SSLContextParameters}}
> (via {{SSLContextParameters.createSSLContext()}}), and pass it down to
> {{AS2AsynchronousMDNManager}} alongside the other MDN settings, the same way
> {{asyncMdnAllowedHosts}} is passed today;
> * when the delivery address uses {{https}}, create the connection from that
> factory instead of {{new Socket(host, port)}}, resolving a missing port to
> 443;
> * apply hostname verification;
> * keep {{https}} refused when no {{SSLContextParameters}} is configured, so
> the fail-closed behaviour introduced by CAMEL-24417 is preserved for a
> deployment that has not opted in;
> * relax the {{http}}-only check to allow {{https}} once a factory is
> available, and update the 4.x upgrade guide note accordingly.
> Note that {{AS2ConnectionHelper}} caches server connections per port, so like
> every other server-side option the TLS configuration would be per port and
> the first endpoint on that port wins.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)