[8u] RFR: 8172404: Tools should warn if weak algorithms are used before restricting them

Andrew Hughes gnu.andrew at redhat.com
Mon Feb 8 05:39:57 UTC 2021


On 20:18 Thu 04 Feb     , Severin Gehwolf wrote:
>

snip...

> > 2. The test/sun/security/tools/keytool/WeakAlg.java changes
> > look quite different when comparing the 11u & 8u patches. Can
> > you confirm the patched files are the same (or close enough)?
> 
> Yes, this is what I've used to arrive at the result. Looking at the JDK
> 11 code. Here is a diff (seems close enough to me):
> https://cr.openjdk.java.net/~sgehwolf/webrevs/JDK-8172404/jdk8/02/WeakAlg.java.jdk8-jdk11.diff
>

I agree, just expected 11u differences. If Martin is happy, feel free to flag this for approval.

Thanks,
-- 
Andrew :)

Senior Free Java Software Engineer
OpenJDK Package Owner
Red Hat, Inc. (http://www.redhat.com)

PGP Key: ed25519/0xCFDA0F9B35964222 (hkp://keys.gnupg.net)
Fingerprint = 5132 579D D154 0ED2 3E04  C5A0 CFDA 0F9B 3596 4222


More information about the jdk8u-dev mailing list