[jdk11u-dev] RFR: 8369282: Distrust TLS server certificates anchored by Chunghwa ePKI Root CA
Severin Gehwolf
sgehwolf at openjdk.org
Wed Feb 18 13:25:55 UTC 2026
On Tue, 17 Feb 2026 15:32:24 GMT, David Sladký <duke at openjdk.org> wrote:
> Backport of [JDK-8369282](https://bugs.openjdk.org/browse/JDK-8369282) - Distrust TLS server certificates anchored by Chunghwa ePKI Root CA
>
> ### Extra changes
>
> **`src/java.base/share/classes/sun/security/validator/ChunghwaTLSPolicy.java:84`**
>
> - return X509CertImpl.getFingerprint("SHA-256", cert, debug);
> + return X509CertImpl.getFingerprint("SHA-256", cert);
>
> - method `getFingerprint()` accepts only two parameters in jdk11.
>
> ### Tests
>
> Tests were run on Fedora 43.
>
> #### Tier 1 - PASSES
>
>
> ==============================
> Test summary
> ==============================
> TEST TOTAL PASS FAIL ERROR
> jtreg:test/hotspot/jtreg:tier1 1530 1530 0 0
> jtreg:test/jdk:tier1 1899 1899 0 0
> jtreg:test/langtools:tier1 3941 3941 0 0
> jtreg:test/nashorn:tier1 0 0 0 0
> jtreg:test/jaxp:tier1 0 0 0 0
> ==============================
> TEST SUCCESS
>
>
> #### `sun/security` - PASSES
>
>
> ==============================
> Test summary
> ==============================
> TEST TOTAL PASS FAIL ERROR
> jtreg:test/jdk/sun/security 665 665 0 0
> ==============================
> TEST SUCCESS
>
>
> #### GHA - PASSES
LGTM
-------------
Marked as reviewed by sgehwolf (Reviewer).
PR Review: https://git.openjdk.org/jdk11u-dev/pull/3157#pullrequestreview-3819893507
More information about the jdk-updates-dev
mailing list