RFR: 8366364: Address inconsistencies in SSLParameters object returned by SSLConfiguration#getSSLParameters() call [v3]

Artur Barashev abarashev at openjdk.org
Tue Oct 28 21:15:33 UTC 2025


On Tue, 28 Oct 2025 20:49:46 GMT, Sean Mullan <mullan at openjdk.org> wrote:

>> Artur Barashev has updated the pull request incrementally with one additional commit since the last revision:
>> 
>>   Log unavailable configured signature scheme
>
> test/jdk/sun/security/ssl/CipherSuite/RestrictNamedGroup.java line 101:
> 
>> 99:             runAndCheckException(() -> new RestrictNamedGroup().run(),
>> 100:                     ex -> assertTrue(ex instanceof NoClassDefFoundError
>> 101:                             || ex instanceof ExceptionInInitializerError));
> 
> I don't understand this change, can you help me understand this better? Why would these exceptions be thrown now?

We do `NamedGroup` constraints check in `NamedGroup.SupportedGroups` now, so the test fails during `SSLConfiguration` object construction and not during TLS handshake as before. One exception is thrown with TLSv1.2 and another with TLSv1.3.

-------------

PR Review Comment: https://git.openjdk.org/jdk/pull/27961#discussion_r2471051783


More information about the security-dev mailing list