[
https://issues.apache.org/jira/browse/CAMEL-25413?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Work on CAMEL-25413 started by Andrea Cosentino.
------------------------------------------------
> camel-kubernetes: trustCerts option misannotated as security=secret instead
> of security=insecure:ssl
> ----------------------------------------------------------------------------------------------------
>
> Key: CAMEL-25413
> URL: https://issues.apache.org/jira/browse/CAMEL-25413
> Project: Camel
> Issue Type: Bug
> Components: camel-kubernetes
> Reporter: Andrea Cosentino
> Assignee: Andrea Cosentino
> Priority: Minor
>
> The trustCerts option in KubernetesConfiguration is annotated with security =
> "secret" but it controls TLS certificate validation - when true, all
> certificates are trusted without verification - not a secret value.
> The correct annotation is security = "insecure:ssl" with insecureValue =
> "true". This way the security policy framework (enabled by camel.main.profile
> = prod) will warn or fail when certificate validation is disabled in a
> production deployment.
> This was introduced by the bulk migration in CAMEL-23250 which mechanically
> converted secret = true to security = "secret" without differentiating
> between actual secrets (passwords, tokens) and insecure configuration flags
> (TLS bypass options).
> Same pattern as the fix applied to camel-hivemq ssl option in CAMEL-24999.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)