[jdk8u-dev] RFR: 8341964: Add mechanism to disable different parts of TLS cipher suite
David Sladký
duke at openjdk.org
Tue Feb 17 12:02:30 UTC 2026
On Tue, 2 Dec 2025 15:36:32 GMT, David Sladký <duke at openjdk.org> wrote:
> Backport of [JDK-8341964](https://bugs.openjdk.org/browse/JDK-8341964) - Add mechanism to disable different parts of TLS cipher suite
>
> Preparation for backport of [JDK-8245545](https://bugs.openjdk.org/browse/JDK-8245545) to comply with [Oracle JRE and JDK Cryptographic Roadmap](https://www.java.com/en/jre-jdk-cryptoroadmap.html)
>
> Tested in RHEL9 VM:
> - Not clean backport.
> - Passed T1 tests.
> - `jdk_security` tests -> 4 fails. Same fails before and after backport. They are unrelated. Probably some incorrect set up in my VM. The failing tests:
> - sun/security/pkcs11/KeyStore/SecretKeysBasic.sh
> - sun/security/pkcs11/Provider/Login.sh
> - sun/security/pkcs11/Signature/TestDSAKeyLength.java
> - sun/security/tools/keytool/autotest.sh
> - GHA -> Linux x86/x64 hotspot/tier1 failing, seems unrelated to this backport, same fails in other already closed and integrated PRs
>
> Extra changes:
> - in `jdk/test/sun/security/ssl/CipherSuite/TLSCipherSuiteWildCardMatchingDisablePartsOfCipherSuite.java` on line 58 changed `List.of()` to `Array.asList()` (and added import for it) because the former is not supported by jdk8.
To be sure I rerun `tier1` and `sun/security` tests
### Tier 1
-------------- Test Summary ------------
Summary: jdk_tier1
TEST STATS: name=jdk_tier1 run=1341 pass=1341 fail=0
Summary: langtools_tier1
FAILED: tools/javac/lambda/LambdaLambdaSerialized.java
TEST STATS: name=langtools_tier1 run=3121 pass=3120 fail=1
Summary: hotspot_tier1
TEST STATS: name=hotspot_tier1 run=808 pass=808 fail=0
I rerun the failed test and it passed:
/root/jtreg/bin/jtreg -jdk:build/linux-x86_64-normal-server-release/images/j2sdk-image -Xmx768m langtools/test/tools/javac/lambda/LambdaLambdaSerialized.java
Test results: passed: 1
### sun/security
Summary:
FAILED: sun/security/pkcs11/KeyStore/SecretKeysBasic.sh
FAILED: sun/security/pkcs11/Provider/Login.sh
FAILED: sun/security/pkcs11/Signature/TestDSAKeyLength.java
FAILED: sun/security/tools/keytool/autotest.sh
These same tests fail both in master and backport branch. I assume this is unrelated to this backport.
### GHA
Passes.
-------------
PR Comment: https://git.openjdk.org/jdk8u-dev/pull/730#issuecomment-3914324750
More information about the jdk8u-dev
mailing list