Re: RFR [14] JDK-8226374 Restrict signature algorithms and named groups

2019-07-11 Thread Xuelei Fan
On 7/10/2019 8:29 AM, Sean Mullan wrote: I think we should modify the description of the jdk.tls.disabledAlgorithms property to state that named groups can also be restricted. For example: diff -r a7b9d6d4940e src/java.base/share/conf/security/java.security --- a/src/java.base/share/conf/secur

RE: [11u] RFR: 8216039: TLS with BC and RSASSA-PSS breaks ECDHServerKeyExchange

2019-07-11 Thread Langer, Christoph
Ping... would somebody please eyeball this backport? No regressions seen in testing... Thanks Christoph From: Langer, Christoph Sent: Donnerstag, 4. Juli 2019 15:11 To: jdk-updates-...@openjdk.java.net Cc: security-dev Subject: [11u] RFR: 8216039: TLS with BC and RSASSA-PSS breaks ECDHServerKe

RE: [11u] RFR: 8216039: TLS with BC and RSASSA-PSS breaks ECDHServerKeyExchange

2019-07-11 Thread Langer, Christoph
Ping... Can somebody please have a look at this backport? Regression testing shows no problems... Thanks Christoph From: Langer, Christoph Sent: Donnerstag, 4. Juli 2019 15:11 To: jdk-updates-...@openjdk.java.net Cc: security-dev Subject: [11u] RFR: 8216039: TLS with BC and RSASSA-PSS breaks