[ 
https://issues.apache.org/jira/browse/CAMEL-25461?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Andrea Cosentino updated CAMEL-25461:
-------------------------------------
    Fix Version/s: 4.22.2
                       (was: 4.22.3)

> camel-thrift - consumer: apply the client authentication of sslParameters
> -------------------------------------------------------------------------
>
>                 Key: CAMEL-25461
>                 URL: https://issues.apache.org/jira/browse/CAMEL-25461
>             Project: Camel
>          Issue Type: Bug
>            Reporter: Andrea Cosentino
>            Assignee: Andrea Cosentino
>            Priority: Major
>             Fix For: 4.18.6, 4.22.2, 4.24.0
>
>
> With {{negotiationType=SSL}} and {{synchronous=true}}, 
> {{ThriftConsumer.initializeServer()}} builds 
> {{TSSLTransportFactory.TSSLTransportParameters}} from only the secure socket 
> protocol, the cipher suites and the key store of {{sslParameters}}. The trust 
> managers and {{serverParameters}} are not used. A 
> {{serverParameters.clientAuthentication}} of {{REQUIRE}} or {{WANT}} 
> therefore has no effect, and the server never requests a client certificate. 
> Components that build their TLS setup from 
> {{SSLContextParameters.createSSLContext()}} do apply these settings.
> Proposal:
> # Create the server socket from 
> {{sslParameters.createSSLContext(camelContext)}}, so that 
> {{serverParameters}} (including {{clientAuthentication}}) and the trust 
> managers apply. One way is to pass an {{SSLServerSocket}} to 
> {{TServerSocket}}. At a minimum, map {{clientAuthentication}} to 
> {{TSSLTransportParameters.requireClientAuth}} together with the trust store.
> # Fail at startup for {{sslParameters}} settings that cannot be applied.
> # Add a test where the client presents no certificate.
> # Document on the component page which {{sslParameters}} settings the 
> consumer supports.
> # Add an upgrade-guide entry.
> _Claude Code on behalf of oscerd_



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to