RFR: 8370885: Default namedGroups values are not being filtered against algorithm constraints

Artur Barashev abarashev at openjdk.org
Wed Nov 19 17:39:08 UTC 2025


NamedGroup.SupportedGroups.namedGroups values are not being filtered against algorithm constraints, unlike other SSLParameters returned by SSLConfiguration#getSSLParameters() call. Those are the values being displayed to the user with "java -XshowSettings:security:tls" command.

Also making changes to avoid needless default group names lookup while we are touching this file.

-------------

Commit messages:
 - 8370885: Default namedGroups values are not being filtered against algorithm constraints

Changes: https://git.openjdk.org/jdk/pull/28397/files
  Webrev: https://webrevs.openjdk.org/?repo=jdk&pr=28397&range=00
  Issue: https://bugs.openjdk.org/browse/JDK-8370885
  Stats: 224 lines in 2 files changed: 153 ins; 41 del; 30 mod
  Patch: https://git.openjdk.org/jdk/pull/28397.diff
  Fetch: git fetch https://git.openjdk.org/jdk.git pull/28397/head:pull/28397

PR: https://git.openjdk.org/jdk/pull/28397


More information about the security-dev mailing list