RFR: 8366364: Return enabled signature schemes with SSLConfiguration#getSSLParameters() call [v3]
Artur Barashev
abarashev at openjdk.org
Wed Oct 29 03:48:01 UTC 2025
On Tue, 28 Oct 2025 22:31:49 GMT, Artur Barashev <abarashev at openjdk.org> wrote:
>> Hmm, I still need more info. Is this a behavior or specification change? Does a standard JSSE API now throw these exceptions instead of `SSLException`?
>
> Correction: `ExceptionInInitializerError` is thrown on the first test iteration and `NoClassDefFoundError` is thrown on the subsequent iterations because the test runs all iterations in the same VM. The exception cause is [still the same](https://github.com/openjdk/jdk/blob/73f93920b950b4ce5fa177db50010e95265d6a7f/src/java.base/share/classes/sun/security/ssl/NamedGroup.java#L780), we would throw the same exception if the named group were unavailable instead of being algorithm-constrained.
On the closer look, I think filtering named groups is better to be dealt with as a separate issue. Removing namedGroup changes and renaming the ticket.
-------------
PR Review Comment: https://git.openjdk.org/jdk/pull/27961#discussion_r2471646995
More information about the security-dev
mailing list