CAMEL-25104: camel-core - SSLContextParameters should use TLSv1.2 as minimum protocol by default - #27008
Conversation
…minimum protocol by default Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Signed-off-by: Claus Ibsen <claus.ibsen@gmail.com>
|
🌟 Thank you for your contribution to the Apache Camel project! 🌟 🐫 Apache Camel Committers, please review the following items:
|
gnodet-bot
left a comment
There was a problem hiding this comment.
Solid change — correct, well-tested, well-documented.
The regex patterns are safe: matcher.matches() is a full-match, so "TLSv1" excludes exactly TLSv1 without touching TLSv1.2/TLSv1.3. The ".*_3DES_.*" pattern correctly targets TLS_RSA_WITH_3DES_EDE_CBC_SHA-style names that ".*_DES_.*" missed.
The SSLServerSocket configurer is now aligned with SSLEngine and SSLSocket — filtering over getSSLParameters().getCipherSuites()/getSSLParameters().getProtocols() (JVM default enabled set) instead of getSupportedCipherSuites()/getSupportedProtocols() (all supported, including insecure). This was the root cause of the server socket enabling TLSv1/TLSv1.1.
Tests cover all three socket types, verify cipher suite parity between engine and server socket, and confirm explicit protocol override still works. Backport labels present for 4.22.x and 4.18.x.
This review was generated by an AI agent, Hermès on behalf of @gnodet.
|
🧪 CI tested the following changed modules:
🔬 Scalpel shadow comparison — Scalpel: 567 of 695 tested, 27 compile-only — current: 568 all testedMaveniverse Scalpel detected 567 affected modules (current approach: 568). Skip-tests mode would test 567 modules (3 direct + 565 downstream), skip tests for 27 (generated code, meta-modules) Modules only in current approach (1)
Modules Scalpel would test (567)
Modules with tests skipped (27)
Build reactor — dependencies compiled but only changed modules were tested (3 modules, 24.1s total)Total reactor time: 24.1s
Top 20 slowest modules:
|
🔄 Backport BotConflicts (🤖 agent dispatched to resolve):
ℹ️ If you push additional commits after |
Implements CAMEL-25104.
The default filters of
SSLContextParametersnow use TLSv1.2 as the minimum protocol:TLSv1andTLSv1.1. Before, it only excludedSSL.*..*_3DES_.*. The existing.*_DES_.*does not match the 3DES suites.SSLServerSocket: the default filters are now applied over the JVM's default enabled protocols and cipher suites, as they already were forSSLSocketandSSLEngine.[TLSv1.3, TLSv1.2, TLSv1.1, TLSv1]on JDK 21/25 unless the JVM security configuration disabled them.An older protocol can still be configured explicitly with
secureSocketProtocols. The documented default filters were outdated and are updated, and the upgrade guide has an entry.Tests
SSLContextParametersDefaultProtocolsTest:SSLEngine,SSLSocketandSSLServerSocketenable only TLSv1.2 or newer;It fails without the fix.
The change should be backported to the supported release lines (4.22.x and 4.18.x).
Claude Code on behalf of Claus Ibsen
🤖 Generated with Claude Code