RFR: backport of JDK-8209916, JDK-8210334, JDK-8210846 to jdk11u

Jamil Nimeh jamil.j.nimeh at oracle.com
Fri Sep 21 06:51:34 UTC 2018


Hello all,

This review is for a backport of 3 TLS interoperability issues that have 
come up over the past week or so.  These are already in jdk/jdk.  They 
cover the following issues:

  * An NPE thrown during processing of the supported groups extension
    with curves not enabled by default
  * A problem processing client hellos where pre_shared_key and
    psk_key_exchange_modes extensions are both omitted
  * A problem where JSSE TLS clients send empty Certificate messages
    during client certificate authentication

Webrev: 
http://cr.openjdk.java.net/~jnimeh/reviews/jdk11u-tls-compat/webrev.01/

JBS Issues:
https://bugs.openjdk.java.net/browse/JDK-8209916
https://bugs.openjdk.java.net/browse/JDK-8210334
https://bugs.openjdk.java.net/browse/JDK-8210846

Thanks,
--Jamil
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://mail.openjdk.org/pipermail/security-dev/attachments/20180920/c80a2ada/attachment.htm>


More information about the security-dev mailing list