Andrea Cosentino created CAMEL-25461:
----------------------------------------

             Summary: camel-thrift - consumer: apply the client authentication 
of sslParameters
                 Key: CAMEL-25461
                 URL: https://issues.apache.org/jira/browse/CAMEL-25461
             Project: Camel
          Issue Type: Bug
            Reporter: Andrea Cosentino
            Assignee: Andrea Cosentino
             Fix For: 4.24.0, 4.18.6, 4.22.3


With {{negotiationType=SSL}} and {{synchronous=true}}, 
{{ThriftConsumer.initializeServer()}} builds 
{{TSSLTransportFactory.TSSLTransportParameters}} from only the secure socket 
protocol, the cipher suites and the key store of {{sslParameters}}. The trust 
managers and {{serverParameters}} are not used. A 
{{serverParameters.clientAuthentication}} of {{REQUIRE}} or {{WANT}} therefore 
has no effect, and the server never requests a client certificate. Components 
that build their TLS setup from {{SSLContextParameters.createSSLContext()}} do 
apply these settings.

Proposal:
# Create the server socket from 
{{sslParameters.createSSLContext(camelContext)}}, so that {{serverParameters}} 
(including {{clientAuthentication}}) and the trust managers apply. One way is 
to pass an {{SSLServerSocket}} to {{TServerSocket}}. At a minimum, map 
{{clientAuthentication}} to {{TSSLTransportParameters.requireClientAuth}} 
together with the trust store.
# Fail at startup for {{sslParameters}} settings that cannot be applied.
# Add a test where the client presents no certificate.
# Document on the component page which {{sslParameters}} settings the consumer 
supports.
# Add an upgrade-guide entry.

_Claude Code on behalf of oscerd_



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to