RFR: 8028192 : Use of PKCS11-NSS provider in FIPS mode broken

Seán Coffey sean.coffey at oracle.com
Thu May 8 15:59:56 UTC 2014


This is more or less a backport of the 8u20 code to the 7u-dev codebase.

This update fixes the SunJSSE problem that in FIPS mode, SunJSSE does
not work because keys cannot be extracted from crypto device.

Builds and tests are good.
http://cr.openjdk.java.net/~coffeys/webrev.8028192.jdk.7udev/webrev/

Regards,
Sean.



More information about the security-dev mailing list