[jdk17u-dev] RFR: 8311546: Certificate name constraints improperly validated with leading period

Aleksey Shipilev shade at openjdk.org
Wed Dec 18 17:24:45 UTC 2024


On Wed, 18 Dec 2024 17:19:07 GMT, Aleksey Shipilev <shade at openjdk.org> wrote:

>> Backporting this due to wider customer interest in aligning JDK behavior with other SSL implementations. Both patches apply cleanly. First patch does the fix. Second patch fixes the test.
>> 
>> Additional testing:
>>  - [x] macos-aarch64-server-release, new test passes with and without the change
>>  - [x] macos-aarch64-server-release, `sun/security/x509/`
>>  - [x] linux-x86_64-server-release, `jdk_security`
>
> Both backports are actually clean.

> @shipilev The `/clean` pull request command is not enabled for this repository

:( Ok, then I need some reviews, please.

-------------

PR Comment: https://git.openjdk.org/jdk17u-dev/pull/3149#issuecomment-2551884407


More information about the jdk-updates-dev mailing list