Code Review Request 8148108 Disable Diffie-Hellman keys less than 1024 bits

Vincent Ryan vincent.x.ryan at
Fri Mar 4 12:30:01 UTC 2016

Your fix looks fine.

> On 4 Mar 2016, at 11:53, Xuelei Fan < at> wrote:
> Hi,
> Please review the update for JDK-8148108:
> In this update, it is proposed to restrict the use of DH keys less than
> 1024 bits in length in the SSL/TLS/DTLS implementation in JDK 9.  This
> restriction is applied via the Java Security property,
> "jdk.tls.disabledAlgorithms".  This will impact providers that adhere to
> this security property, for example, the SunJSSE provider.
> Thanks,
> Xuelei

