RFR: 8320449: ECDHKeyAgreement should validate parameters before using them

Sean Mullan mullan at openjdk.org
Fri Jan 12 13:49:20 UTC 2024


On Thu, 11 Jan 2024 13:33:54 GMT, John Jiang <jjiang at openjdk.org> wrote:

> ECDHKeyAgreement should validate the parameters before assigning them to the fields.

src/java.base/share/classes/sun/security/ec/ECDHKeyAgreement.java line 83:

> 81:         privateKey = null;
> 82:         privateKeyOps = null;
> 83:         publicKey = null;

The fields should be initialized to null, so I don't think you need these lines.

-------------

PR Review Comment: https://git.openjdk.org/jdk/pull/17373#discussion_r1450474761



More information about the security-dev mailing list