On Thu, 2 Oct 2025 11:29:12 GMT, Matthew Donovan <[email protected]> wrote:

> > I think we should either implement a public API to provide those signature 
> > schemes or not display them at all to avoid any confusion. If someone sets 
> > `jdk.tls.client.SignatureSchemes` system property they would sure know 
> > about it. That property overrides all other signature schemes for both 
> > "signature_algorithms" and "signature_algorithms_cert" extensions.
> 
> I removed the signature algorithms from this output. If accurate lists aren't 
> generated until TLS handshake, then I don't think there's any reason to print 
> a list here.

Sounds good. I've created 
[JDK-8366364](https://bugs.openjdk.org/browse/JDK-8366364) to address this 
problem. Once it's done we can include signature algorithms in the output.

-------------

PR Comment: https://git.openjdk.org/jdk/pull/24424#issuecomment-3361286352

Reply via email to