JEP proposed to target JDK 27: 527: Post-Quantum Hybrid Key Exchange for TLS 1.3

Mark Reinhold mark.reinhold at oracle.com
Tue Jan 20 13:50:08 UTC 2026


2026/1/12 14:52:43 -0500, Mark Reinhold:
> The following JEP is proposed to target JDK 27:
>
>   527: Post-Quantum Hybrid Key Exchange for TLS 1.3
>      https://openjdk.org/jeps/527
>
>   Summary: Enhance the security of Java applications that require secure
>   network communication by implementing hybrid key exchange algorithms
>   for TLS 1.3.  Such algorithms defend against future quantum computing
>   attacks by combining a quantum-resistant algorithm with a traditional
>   algorithm.  Applications that use the javax.net.ssl APIs will benefit
>   from these improved algorithms by default, without change to existing
>   code.
>
> Feedback on this proposal from JDK Project Committers and Reviewers [1]
> is more than welcome, as are reasoned objections.  If no such objections
> are raised by 20:00 UTC on Monday, 19 January, or if they’re raised and
> then satisfactorily answered, then per the JEP 2.0 process proposal [2]
> I’ll target this JEP to JDK 27.

Hearing no objections, I’ve targeted this JEP to JDK 27.

- Mark


More information about the jdk-dev mailing list