RFR: 8312428: PKCS11 tests fail with NSS 3.91 [v4]

Rajan Halade rhalade at openjdk.org
Tue Aug 29 16:47:13 UTC 2023


On Fri, 25 Aug 2023 22:42:05 GMT, Valerie Peng <valeriep at openjdk.org> wrote:

>> Starting NSS v3.91, SHA-3 support is added for MessageDigest but not for PSS Signature. This breaks existing test assumptions made by PSS regression tests. In addition, the NSS SHA-3 message digests do not support cloning which causes the failure of TestCloning.java.
>> 
>> This PR adds a PSSUtil.java class which provides utility method for detecting/guessing whether a digest algorithm is valid for PSS signature or not.
>> 
>> The changes are verified with NSS v3.46, v3.57 and v3.91 (on local Linux machine).
>> 
>> Thanks in advance for review~
>
> Valerie Peng has updated the pull request incrementally with one additional commit since the last revision:
> 
>   address more review feedbacks

Marked as reviewed by rhalade (Reviewer).

-------------

PR Review: https://git.openjdk.org/jdk/pull/15217#pullrequestreview-1600868746


More information about the security-dev mailing list