[
https://issues.apache.org/jira/browse/CAMEL-24790?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Andrea Cosentino reassigned CAMEL-24790:
----------------------------------------
Assignee: Andrea Cosentino
> camel-oauth: remove unused expired demo certificate and private key from
> helm/etc
> ---------------------------------------------------------------------------------
>
> Key: CAMEL-24790
> URL: https://issues.apache.org/jira/browse/CAMEL-24790
> Project: Camel
> Issue Type: Task
> Components: camel-oauth
> Reporter: Andrea Cosentino
> Assignee: Andrea Cosentino
> Priority: Major
>
> h3. Summary
> {{components/camel-oauth/helm/etc/cluster.crt}} and
> {{components/camel-oauth/helm/etc/cluster.key}} are a committed self-signed
> certificate and its matching RSA private key. They are demo material for the
> local Keycloak setup.
> Two problems:
> * The certificate expired on *16 Apr 2026*, so it is no longer usable as demo
> material.
> * Nothing in the Helm chart actually consumes these files. {{helm/README.md}}
> instructs the user to generate their own certificate with {{mkcert}} and
> create the {{edge-tls}} secret from that. The {{cluster.crt}} references in
> {{oauth.adoc}} point at a file the reader generates at runtime with {{openssl
> s_client}}, not at the committed one.
> The only consumer is {{SSLCertTrustTest.testCheckClusterCertificateTrust}},
> which reads {{helm/etc/cluster.crt}} and then logs either "Trusted" or
> "Untrusted" without asserting anything, so it passes regardless of the
> outcome. The whole test class is additionally gated behind
> {{Assumptions.assumeTrue(admin.isKeycloakRunning())}}.
> h3. Proposal
> Remove both files and drop the assertion-free test that reads them. Checking
> in a private key has no upside here even for demo material, and regenerating
> it would only re-arm the same expiry in a year while keeping the key in git
> history.
> No user-facing behaviour changes; the documented workflow already has the
> reader generate their own certificate.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)