[jdk8u-dev] RFR: 8341964: Add mechanism to disable different parts of TLS cipher suite

David Sladký duke at openjdk.org
Tue Feb 17 12:02:30 UTC 2026


On Tue, 2 Dec 2025 15:36:32 GMT, David Sladký <duke at openjdk.org> wrote:

> Backport of [JDK-8341964](https://bugs.openjdk.org/browse/JDK-8341964) - Add mechanism to disable different parts of TLS cipher suite
> 
> Preparation for backport of [JDK-8245545](https://bugs.openjdk.org/browse/JDK-8245545) to comply with [Oracle JRE and JDK Cryptographic Roadmap](https://www.java.com/en/jre-jdk-cryptoroadmap.html)
> 
> Tested in RHEL9 VM:
> - Not clean backport.
> - Passed T1 tests.
> - `jdk_security` tests -> 4 fails. Same fails before and after backport. They are unrelated. Probably some incorrect set up in my VM. The failing tests:
> 	- sun/security/pkcs11/KeyStore/SecretKeysBasic.sh
> 	- sun/security/pkcs11/Provider/Login.sh
> 	- sun/security/pkcs11/Signature/TestDSAKeyLength.java
> 	- sun/security/tools/keytool/autotest.sh
> - GHA -> Linux x86/x64 hotspot/tier1 failing, seems unrelated to this backport, same fails in other already closed and integrated PRs
> 
> Extra changes:
> - in `jdk/test/sun/security/ssl/CipherSuite/TLSCipherSuiteWildCardMatchingDisablePartsOfCipherSuite.java` on line 58 changed `List.of()` to `Array.asList()` (and added import for it) because the former is not supported by jdk8.

To be sure I rerun `tier1` and `sun/security` tests

### Tier 1


-------------- Test Summary ------------

Summary: jdk_tier1
TEST STATS: name=jdk_tier1  run=1341  pass=1341  fail=0

Summary: langtools_tier1
FAILED: tools/javac/lambda/LambdaLambdaSerialized.java
TEST STATS: name=langtools_tier1  run=3121  pass=3120  fail=1

Summary: hotspot_tier1
TEST STATS: name=hotspot_tier1  run=808  pass=808  fail=0

I rerun the failed test and it passed:

/root/jtreg/bin/jtreg -jdk:build/linux-x86_64-normal-server-release/images/j2sdk-image -Xmx768m langtools/test/tools/javac/lambda/LambdaLambdaSerialized.java
Test results: passed: 1


### sun/security


Summary:
FAILED: sun/security/pkcs11/KeyStore/SecretKeysBasic.sh
FAILED: sun/security/pkcs11/Provider/Login.sh
FAILED: sun/security/pkcs11/Signature/TestDSAKeyLength.java
FAILED: sun/security/tools/keytool/autotest.sh


These same tests fail both in master and backport branch. I assume this is unrelated to this backport.

### GHA

Passes.

-------------

PR Comment: https://git.openjdk.org/jdk8u-dev/pull/730#issuecomment-3914324750


More information about the jdk8u-dev mailing list