Andrea Cosentino created CAMEL-25461:
----------------------------------------
Summary: camel-thrift - consumer: apply the client authentication
of sslParameters
Key: CAMEL-25461
URL: https://issues.apache.org/jira/browse/CAMEL-25461
Project: Camel
Issue Type: Bug
Reporter: Andrea Cosentino
Assignee: Andrea Cosentino
Fix For: 4.24.0, 4.18.6, 4.22.3
With {{negotiationType=SSL}} and {{synchronous=true}},
{{ThriftConsumer.initializeServer()}} builds
{{TSSLTransportFactory.TSSLTransportParameters}} from only the secure socket
protocol, the cipher suites and the key store of {{sslParameters}}. The trust
managers and {{serverParameters}} are not used. A
{{serverParameters.clientAuthentication}} of {{REQUIRE}} or {{WANT}} therefore
has no effect, and the server never requests a client certificate. Components
that build their TLS setup from {{SSLContextParameters.createSSLContext()}} do
apply these settings.
Proposal:
# Create the server socket from
{{sslParameters.createSSLContext(camelContext)}}, so that {{serverParameters}}
(including {{clientAuthentication}}) and the trust managers apply. One way is
to pass an {{SSLServerSocket}} to {{TServerSocket}}. At a minimum, map
{{clientAuthentication}} to {{TSSLTransportParameters.requireClientAuth}}
together with the trust store.
# Fail at startup for {{sslParameters}} settings that cannot be applied.
# Add a test where the client presents no certificate.
# Document on the component page which {{sslParameters}} settings the consumer
supports.
# Add an upgrade-guide entry.
_Claude Code on behalf of oscerd_
--
This message was sent by Atlassian Jira
(v8.20.10#820010)