JiriOndrusek opened a new issue, #9263:
URL: https://github.com/apache/camel-quarkus/issues/9263

   Since Quarkus 3.39 the TLS registry configures post-quantum key exchange 
with `quarkus.tls.pqc-enforcement-policy` (and optionally 
`quarkus.tls.key-exchange-groups`). With JEP 527 the JDK's own TLS 
implementation negotiates the hybrid X25519MLKEM768 group, so no security 
provider or native library is needed.
   
   Add an `http-pqc-j25` example to camel-quarkus-examples: a `platform-http` 
endpoint behind mutual TLS, with the `client-negotiated` policy by default and 
a `strict` profile that rejects classical clients.
   
   Today only Java 27 supports this (JEP 527 shipped on 15 September 2026). JDK 
25 is expected to get the backport with its October 2026 update (JDK-8387671, 
fixed for 25.0.5), JDK 21 and 17 in 2027. The example detects the support at 
runtime, so its tests are skipped on older JDKs and CI (JDK 17 and 21) only 
compiles it. Native mode needs a GraalVM/Mandrel built on such a JDK, not 
available yet.
   
   The existing `http-pqc-j21` example keeps its BouncyCastle JSSE approach for 
older JDKs.
   
   _Claude Code on behalf of Jiří Ondrušek_


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to