git: openjdk/jdk: master: 8367104: Check for RSASSA-PSS parameters when validating certificates against algorithm constraints

Artur Barashev abarashev at openjdk.org
Fri Sep 19 13:13:50 UTC 2025


Changeset: 3798dcf7
Branch: master
Author:    Artur Barashev <abarashev at openjdk.org>
Date:      2025-09-19 13:06:25 +0000
URL:       https://git.openjdk.org/jdk/commit/3798dcf75b547a3707cdfdacf62886648c8653cf

8367104: Check for RSASSA-PSS parameters when validating certificates against algorithm constraints

Reviewed-by: mullan

! src/java.base/share/classes/sun/security/provider/certpath/AlgorithmChecker.java
! src/java.base/share/classes/sun/security/provider/certpath/PKIXCertPathValidator.java
! src/java.base/share/classes/sun/security/ssl/SSLAlgorithmConstraints.java
! src/java.base/share/classes/sun/security/ssl/SSLContextImpl.java
! src/java.base/share/classes/sun/security/ssl/SSLSessionImpl.java
! src/java.base/share/classes/sun/security/ssl/SignatureScheme.java
! src/java.base/share/classes/sun/security/ssl/X509KeyManagerCertChecking.java
! src/java.base/share/classes/sun/security/ssl/X509TrustManagerImpl.java
! src/java.base/share/classes/sun/security/validator/PKIXValidator.java
! test/jdk/sun/security/ssl/SignatureScheme/MD5NotAllowedInTLS13CertificateSignature.java
+ test/jdk/sun/security/ssl/SignatureScheme/RsaSsaPssConstraints.java
+ test/jdk/sun/security/ssl/X509TrustManagerImpl/CertChainAlgorithmConstraints.java



More information about the jdk-changes mailing list