RFR: 8028192 : Use of PKCS11-NSS provider in FIPS mode broken

Xuelei Fan xuelei.fan at oracle.com
Fri May 9 09:28:05 UTC 2014


Looks fine to me.

Thanks,
Xuelei

On 5/8/2014 11:59 PM, Seán Coffey wrote:
> This is more or less a backport of the 8u20 code to the 7u-dev codebase.
> 
> This update fixes the SunJSSE problem that in FIPS mode, SunJSSE does
> not work because keys cannot be extracted from crypto device.
> 
> Builds and tests are good.
> http://cr.openjdk.java.net/~coffeys/webrev.8028192.jdk.7udev/webrev/
> 
> Regards,
> Sean.



More information about the security-dev mailing list