RFR: 8370885: Default namedGroups values are not being filtered against algorithm constraints [v2]
Artur Barashev
abarashev at openjdk.org
Tue Nov 25 21:56:19 UTC 2025
> NamedGroup.SupportedGroups.namedGroups values are not being filtered against algorithm constraints, unlike other SSLParameters returned by SSLConfiguration#getSSLParameters() call. Those are the values being displayed to the user with "java -XshowSettings:security:tls" command.
>
> Also making changes to avoid needless default group names lookup while we are touching this file.
Artur Barashev has updated the pull request with a new target base due to a merge or a rebase. The pull request now contains two commits:
- Merge branch 'master' into JDK-8370885
# Conflicts:
# src/java.base/share/classes/sun/security/ssl/NamedGroup.java
- 8370885: Default namedGroups values are not being filtered against algorithm constraints
-------------
Changes: https://git.openjdk.org/jdk/pull/28397/files
Webrev: https://webrevs.openjdk.org/?repo=jdk&pr=28397&range=01
Stats: 224 lines in 2 files changed: 153 ins; 41 del; 30 mod
Patch: https://git.openjdk.org/jdk/pull/28397.diff
Fetch: git fetch https://git.openjdk.org/jdk.git pull/28397/head:pull/28397
PR: https://git.openjdk.org/jdk/pull/28397
More information about the security-dev
mailing list