← Back to all articles

Spring Boot 4.2.0-M2 Released: SSL Bundle Support for LDAP and OpenTelemetry Conventions

JavaObservabilitySecurity

What this release is

Spring Boot 4.2.0-M2 was released on September 25, 2026 and is available from Maven Central. The team counts 141 enhancements, documentation improvements, dependency upgrades and bug fixes. It is the second milestone on the 4.2 line, meant for early adopters to validate changes ahead of time rather than for production use.

The two features the announcement singles out are SSL bundle support for LDAP and alignment with OpenTelemetry's semantic conventions. On top of that, there are several changes to handle when coming from 4.1, listed below in order of impact.

LDAP gets full SSL bundle support

Previously, making the auto-configured LdapContextSource talk LDAPS meant assembling the SSL configuration yourself. Now you can point at an SSL bundle directly: set spring.ldap.ssl.bundle and write spring.ldap.urls as an ldaps:// URL. Once a bundle is configured, that property defaults to ldaps://localhost:636. If you only need the platform's default trust material, spring.ldap.ssl.enabled=true is enough.

Reloaded bundle key and trust material is picked up by subsequent connections, so there is no need to restart the application.

The embedded LDAP server changes more thoroughly: it now supports LDAPS too, and naming a bundle with spring.ldap.embedded.ssl.bundle configures both ends at once, so an auto-configured LdapTemplate or LdapContextSource can connect without any client-side setup. Accordingly, while the embedded server is in use, spring.ldap.urls, username, password and ssl.* are ignored in favour of spring.ldap.embedded.*, because only the server knows what a connection to it looks like.

One more detail worth noting: setting spring.ldap.embedded.ssl.enabled to true without a bundle used to start a plain listener silently; it now fails fast and asks for the bundle. To control which operations require authentication, use spring.ldap.embedded.authentication-required-operation-types.

Observability aligned with OpenTelemetry

Set management.observations.conventions to open-telemetry to switch to OpenTelemetry's semantic conventions. Note that only stable conventions are covered, and that once enabled, properties customising meter names such as management.observations.http.server.requests.name no longer take effect, because names are then dictated by the OTel conventions.

OTLP export configuration is now unified as well: endpoint, headers and compression can be set once under management.opentelemetry.otlp and shared by the tracing, logging and metrics exporters. Signal-specific properties still take precedence when set and fall back to the common value otherwise. For HTTP transport, the endpoint gets the /v1/traces, /v1/logs or /v1/metrics path appended automatically.

In addition, the MDC keys used by Micrometer Tracing for the trace and span IDs can now be customised via management.tracing.mdc.trace-id-key and management.tracing.mdc.span-id-key. They default to traceId and spanId, and apply to both OpenTelemetry and Brave.

Four changes to handle when upgrading from 4.1

  • Tomcat properties moved: server.tomcat.additional-tld-skip-patterns, redirect-context-root and use-relative-redirects now live under server.tomcat.servlet.*. use-relative-redirects also defaults to true, aligning with Tomcat's own default; set it to false explicitly to keep the old behaviour.
  • Janino dependency management removed: this follows Logback dropping Janino support. If your application still uses Janino, manage its version in your own build.
  • Micrometer conventions split and renamed: JvmMemoryMeterConventions, JvmThreadMeterConventions, JvmClassLoadingMeterConventions and JvmCpuMeterConventions have been split into finer-grained individual conventions, and the application fails to start if a deprecated convention and one of its replacements both exist. Separately, management.metrics.observations.ignored-meters has been removed and LongTaskTimer is no longer created by default; set management.metrics.observations.include-active-long-task-timer to true if you want it back.
  • SSL required for the embedded LDAP server: the one described above — enable SSL and you must supply a bundle.

Also worth knowing

@DefaultValue now supports property placeholders, and any placeholders in default values are resolved as part of the binding process. Kafka auto-configuration can wire a dedicated KafkaAdmin for the KafkaTemplate and for listener containers, under the spring.kafka.template.admin and spring.kafka.listener.admin namespaces. When defining a custom message source, a ResourceBasedMessageSourceConfigurer is now auto-configured to apply the spring.messages.* properties for you. And the tools jar mode gained an sbom command that prints and exports the SBOM packaged inside an uber jar or war.

On the dependency side, Spring Framework moves to 7.1.0-M2, with Spring Data 2026.1.0-M2, Spring Batch 6.1.0-M2, Spring Integration 7.2.0-M2 and Spring Kafka 4.2.0-M2 following along; among third-party libraries, Kotlin 2.4.20, Groovy 5.1.2, Lettuce 7.7.0, MongoDB 5.11.1 and Selenium 4.49.0 all moved up.

How to treat this release

The point of a milestone is to surface changes early. What is worth doing now is validating two things on a separate branch: whether your LDAP configuration still behaves as expected, especially tests that mix the embedded server with production settings; and, if you plan to switch to OpenTelemetry conventions, whether the resulting meter-name changes break existing dashboards or alerts. The rest can wait until RC and GA.