allthingssecurity opened a new pull request, #27319: URL: https://github.com/apache/camel/pull/27319
# Description [CAMEL-25287](https://issues.apache.org/jira/browse/CAMEL-25287) Since `sslContextParameters` was added (CAMEL-20393, #14998, Camel 4.8), `SplunkHECProducer.doStart` builds its HTTPS socket factory from `endpoint.provideSSLContext()`. That method returns `null` when neither the endpoint nor the component has `sslContextParameters` (the default), and HttpClient 5 rejects a null SSL context: the producer fails to start with `NullPointerException: SSL context`, with `https=true` as well as `https=false`. Only `skipTlsVerify=true` or configured `sslContextParameters` worked. The existing unit tests inject a mock HTTP client and never start the producer. This change: without an SSL context from `sslContextParameters`, the producer uses `SSLConnectionSocketFactory.getSocketFactory()`, HttpClient's default TLS set-up (`SSLContexts.createDefault()`: the JVM default trust store and the default hostname verifier, as CAMEL-23505 intended). That is what the producer used before 4.8 through the default `PoolingHttpClientConnectionManager`. Certificate and hostname verification stay on; only `skipTlsVerify=true` turns them off, as before. Tests: - `SplunkHECProducerHttpTest` (new, a JDK `HttpServer` as HEC endpoint): the producer starts without `sslContextParameters`; with `https=false` an event reaches the server; control: the same with `sslContextParameters` configured. - Without the change 2 fail (`NullPointerException: SSL context`); the control passes. - With the change the module suite passes (33 tests, 2 skipped manual ITs). # Target - [x] I checked that the commit is targeting the correct branch (Camel 4 uses the `main` branch) # Tracking - [x] If this is a large change, bug fix, or code improvement, I checked there is a [JIRA issue](https://issues.apache.org/jira/browse/CAMEL) filed for the change (usually before you start working on it). # Apache Camel coding standards and style - [x] I checked that each commit in the pull request has a meaningful subject line and body. - [ ] I have run `mvn clean install -DskipTests` locally from root folder and I have committed all auto-generated changes. (I built and tested the affected module, including the formatter and import-sort plugins. I did not run the full root build.) # AI-assisted contributions - [x] If this PR includes AI-generated code, commits have proper co-authorship attribution (e.g., `Co-authored-by` trailers) and the PR description identifies the AI tool used. This PR was prepared with Claude Code (Claude Opus 5.5). The commit carries a `Co-Authored-By` trailer. _Claude Code on behalf of allthingssecurity_ 🤖 Generated with [Claude Code](https://claude.com/claude-code) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
