RFC 7627 functionality (session hash and extended master secret extension) in JSSE?

coderaptor coderaptor at gmail.com
Wed Jan 27 17:23:07 UTC 2016


When would the TLS protocol changes as defined by RFC 7627 be
committed to JSSE? So far my search has turned up nothing (no open
feature request or bug on OpenJDK, nor anything in web-searches). I
realize the RFC was finalized fairly recent, and the mitigation has
been in JSSE for a while now.

Thanks in advance.

-Amarendra

P.S.: My first mail to the list, and apologies if I've missed any
etiquette (though I tried hard not to).



More information about the security-dev mailing list