RFR: 8366364: Address inconsistencies in SSLParameters object returned by SSLConfiguration#getSSLParameters() call [v3]
Artur Barashev
abarashev at openjdk.org
Tue Oct 28 21:15:33 UTC 2025
On Tue, 28 Oct 2025 20:49:46 GMT, Sean Mullan <mullan at openjdk.org> wrote:
>> Artur Barashev has updated the pull request incrementally with one additional commit since the last revision:
>>
>> Log unavailable configured signature scheme
>
> test/jdk/sun/security/ssl/CipherSuite/RestrictNamedGroup.java line 101:
>
>> 99: runAndCheckException(() -> new RestrictNamedGroup().run(),
>> 100: ex -> assertTrue(ex instanceof NoClassDefFoundError
>> 101: || ex instanceof ExceptionInInitializerError));
>
> I don't understand this change, can you help me understand this better? Why would these exceptions be thrown now?
We do `NamedGroup` constraints check in `NamedGroup.SupportedGroups` now, so the test fails during `SSLConfiguration` object construction and not during TLS handshake as before. One exception is thrown with TLSv1.2 and another with TLSv1.3.
-------------
PR Review Comment: https://git.openjdk.org/jdk/pull/27961#discussion_r2471051783
More information about the security-dev
mailing list