RFR: 8349583: Add mechanism to disable signature schemes based on their TLS scope [v12]
Artur Barashev
abarashev at openjdk.org
Wed Mar 5 01:14:40 UTC 2025
> Currently when a signature scheme constraint is specified with "jdk.tls.disabledAlgorithms" property we don't differentiate between signatures used to sign a TLS handshake exchange and the signatures used in TLS certificates:
> https://datatracker.ietf.org/doc/html/rfc8446#section-4.2.3
>
> Also fixing JDK-8350807 on the server side just as a side-effect, not a dedicated fix for that issue.
Artur Barashev has updated the pull request incrementally with one additional commit since the last revision:
Update documentation and unit tests to signal TLS scope case-insensitivity
-------------
Changes:
- all: https://git.openjdk.org/jdk/pull/23681/files
- new: https://git.openjdk.org/jdk/pull/23681/files/bc8d933e..efb11851
Webrevs:
- full: https://webrevs.openjdk.org/?repo=jdk&pr=23681&range=11
- incr: https://webrevs.openjdk.org/?repo=jdk&pr=23681&range=10-11
Stats: 4 lines in 3 files changed: 0 ins; 0 del; 4 mod
Patch: https://git.openjdk.org/jdk/pull/23681.diff
Fetch: git fetch https://git.openjdk.org/jdk.git pull/23681/head:pull/23681
PR: https://git.openjdk.org/jdk/pull/23681
More information about the security-dev
mailing list