[
https://issues.apache.org/jira/browse/CAMEL-25461?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Andrea Cosentino updated CAMEL-25461:
-------------------------------------
Fix Version/s: 4.22.2
(was: 4.22.3)
> camel-thrift - consumer: apply the client authentication of sslParameters
> -------------------------------------------------------------------------
>
> Key: CAMEL-25461
> URL: https://issues.apache.org/jira/browse/CAMEL-25461
> Project: Camel
> Issue Type: Bug
> Reporter: Andrea Cosentino
> Assignee: Andrea Cosentino
> Priority: Major
> Fix For: 4.18.6, 4.22.2, 4.24.0
>
>
> With {{negotiationType=SSL}} and {{synchronous=true}},
> {{ThriftConsumer.initializeServer()}} builds
> {{TSSLTransportFactory.TSSLTransportParameters}} from only the secure socket
> protocol, the cipher suites and the key store of {{sslParameters}}. The trust
> managers and {{serverParameters}} are not used. A
> {{serverParameters.clientAuthentication}} of {{REQUIRE}} or {{WANT}}
> therefore has no effect, and the server never requests a client certificate.
> Components that build their TLS setup from
> {{SSLContextParameters.createSSLContext()}} do apply these settings.
> Proposal:
> # Create the server socket from
> {{sslParameters.createSSLContext(camelContext)}}, so that
> {{serverParameters}} (including {{clientAuthentication}}) and the trust
> managers apply. One way is to pass an {{SSLServerSocket}} to
> {{TServerSocket}}. At a minimum, map {{clientAuthentication}} to
> {{TSSLTransportParameters.requireClientAuth}} together with the trust store.
> # Fail at startup for {{sslParameters}} settings that cannot be applied.
> # Add a test where the client presents no certificate.
> # Document on the component page which {{sslParameters}} settings the
> consumer supports.
> # Add an upgrade-guide entry.
> _Claude Code on behalf of oscerd_
--
This message was sent by Atlassian Jira
(v8.20.10#820010)