[8u] RFR: JDK-8236512: PKCS11 Connection closed after Cipher.doFinal and NoPadding

Andrew Hughes gnu.andrew at redhat.com
Thu Oct 8 16:05:37 UTC 2020


On 14:29 Thu 08 Oct     , Andrew Haley wrote:
> On 08/10/2020 06:10, Andrew Hughes wrote:
> > [0]https://bugs.openjdk.java.net/browse/JDK-8235215
> >
> > Ok for 8u-dev?
> 
> OK. I see that the root cause of this was a backport of 6946830, a fix
> that was required for Marin Balao's fix of 6913047, Long term memory
> leak when using PKCS11 and JCE exceeds 32 bit process address space,
> which in turn caused 8216597.
> 
> What a tangled web we weave...
> 
> -- 
> Andrew Haley  (he/him)
> Java Platform Lead Engineer
> Red Hat UK Ltd. <https://www.redhat.com>
> https://keybase.io/andrewhaley
> EAC8 43EB D3EF DB98 CC77 2FAD A5CD 6035 332F A671
> 

Indeed. Thanks for the further history on this.

It seems the PKCS11 stack has not been heavily tested. We're finding
quite a lot of issues through our work on using it for FIPS provision
in RHEL.

Thanks,
-- 
Andrew :)

Senior Free Java Software Engineer
OpenJDK Package Owner
Red Hat, Inc. (http://www.redhat.com)

PGP Key: ed25519/0xCFDA0F9B35964222 (hkp://keys.gnupg.net)
Fingerprint = 5132 579D D154 0ED2 3E04  C5A0 CFDA 0F9B 3596 4222


More information about the jdk8u-dev mailing list