[ 
https://issues.apache.org/jira/browse/CAMEL-24790?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Andrea Cosentino reassigned CAMEL-24790:
----------------------------------------

    Assignee: Andrea Cosentino

> camel-oauth: remove unused expired demo certificate and private key from 
> helm/etc
> ---------------------------------------------------------------------------------
>
>                 Key: CAMEL-24790
>                 URL: https://issues.apache.org/jira/browse/CAMEL-24790
>             Project: Camel
>          Issue Type: Task
>          Components: camel-oauth
>            Reporter: Andrea Cosentino
>            Assignee: Andrea Cosentino
>            Priority: Major
>
> h3. Summary
> {{components/camel-oauth/helm/etc/cluster.crt}} and 
> {{components/camel-oauth/helm/etc/cluster.key}} are a committed self-signed 
> certificate and its matching RSA private key. They are demo material for the 
> local Keycloak setup.
> Two problems:
> * The certificate expired on *16 Apr 2026*, so it is no longer usable as demo 
> material.
> * Nothing in the Helm chart actually consumes these files. {{helm/README.md}} 
> instructs the user to generate their own certificate with {{mkcert}} and 
> create the {{edge-tls}} secret from that. The {{cluster.crt}} references in 
> {{oauth.adoc}} point at a file the reader generates at runtime with {{openssl 
> s_client}}, not at the committed one.
> The only consumer is {{SSLCertTrustTest.testCheckClusterCertificateTrust}}, 
> which reads {{helm/etc/cluster.crt}} and then logs either "Trusted" or 
> "Untrusted" without asserting anything, so it passes regardless of the 
> outcome. The whole test class is additionally gated behind 
> {{Assumptions.assumeTrue(admin.isKeycloakRunning())}}.
> h3. Proposal
> Remove both files and drop the assertion-free test that reads them. Checking 
> in a private key has no upside here even for demo material, and regenerating 
> it would only re-arm the same expiry in a year while keeping the key in git 
> history.
> No user-facing behaviour changes; the documented workflow already has the 
> reader generate their own certificate.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to