[ 
https://issues.apache.org/jira/browse/CAMEL-24785?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18116268#comment-18116268
 ] 

Andrea Cosentino commented on CAMEL-24785:
------------------------------------------

Fixed via #26524 (squash-merged to main, 4.23.0): 
https://github.com/apache/camel/pull/26524 (commit 0076168a5cd4).

_Claude Code on behalf of Andrea Cosentino (@oscerd)_

> camel-opa - support sslContextParameters for the connection to the OPA server
> -----------------------------------------------------------------------------
>
>                 Key: CAMEL-24785
>                 URL: https://issues.apache.org/jira/browse/CAMEL-24785
>             Project: Camel
>          Issue Type: Improvement
>            Reporter: Andrea Cosentino
>            Assignee: Andrea Cosentino
>            Priority: Major
>             Fix For: 4.23.0
>
>
> h2. Problem
> {{camel-opa}} has no way to configure TLS for the connection to the OPA 
> server. There is no {{sslContextParameters}} option, and the component builds 
> its client through {{new OPAClient(serverUrl)}}, which leaves the SDK on 
> {{HttpClient.newHttpClient()}} and therefore the JVM default trust material.
> That means an operator cannot:
> * point {{camel-opa}} at an HTTPS OPA server whose certificate is issued by a 
> private CA, without importing it into the JVM truststore for the whole 
> application;
> * present a client certificate to an OPA server that requires mutual TLS.
> The second is the one that stings. {{camel-opa}} and {{camel-spiffe}} were 
> designed as a pair - SPIFFE establishes *who*, OPA decides *whether* - but a 
> SPIFFE X.509-SVID cannot currently be used to authenticate to the policy 
> decision point, even though CAMEL-24571 added {{SpiffeSSLContextParameters}} 
> for exactly this shape of problem.
> h2. Fix
> Add {{sslContextParameters}} ({{@UriParam(label = "security")}}) and make the 
> component {{SSLContextParametersAware}} so {{useGlobalSslContextParameters}} 
> works the usual way. Build the shared {{java.net.http.HttpClient}} with 
> {{.sslContext(sslContextParameters.createSSLContext(camelContext))}} and hand 
> it to {{OPAClient(String, HTTPClient)}}.
> h2. Depends on
> The camel-owned {{HTTPClient}} introduced by the sibling issue - there is no 
> other seam to pass an {{SSLContext}} through, since the SDK's default client 
> is hardcoded to {{HttpClient.newHttpClient()}}.
> h2. Scope
> {{main}} only. Additive; with no {{sslContextParameters}} configured the 
> behaviour is unchanged.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to