<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class="">
Hi security-folk,
<div class=""><br class="">
</div>
<div class="">At VMware while upgrading our application to OpenJDK11u, we have encountered what seems to be a serious behavior issue.</div>
<div class="">The issue AFAICT seems to have stemmed from the work for TLS1.3 and <a href="https://bugs.openjdk.java.net/browse/JDK-8196584" class="external-link" rel="nofollow" style="color: rgb(59, 115, 175); text-decoration: none; font-family: Arial, sans-serif; font-size: 14px;">JDK-8196584</a>.</div>
<div class=""><br class="">
</div>
<div class="">Overview:</div>
<div class="">With OpenJDK11 the end-points are closed immediately with TLS alerts raised when an exception is received. </div>
<div class="">This is not the case with JDK8 the socket is not closed allowing retries.</div>
<div class=""><br class="">
</div>
<div class="">I have filed: JDK-8239798 (with a reproducer), this issue was also reported to Azul and they have filed: JDK-8239788.</div>
<div class=""><br class="">
</div>
<div class="">Can you please evaluate this at the earliest, this is a serious show stopper for VMware.</div>
<div class=""><br class="">
</div>
<div class="">Thank</div>
<div class="">Kumar Srinivasan</div>
<div class="">VMware</div>
</body>
</html>