Why no JNDI de-ser killswitch

2021-12-12 Thread Bernd Eckenfels
Hello, I can understand that ldapcontext.lookup() still has to use unsafe deserialisation for legacy reasons (JMS factories etc). But it would be really good if there would be a bit more infra like a killswitch or url-prefix filter JNDI for those who don’t need that. It was a rather damaging m

Integrated: JDK-8278344: sun/security/pkcs12/KeytoolOpensslInteropTest.java test fails because of different openssl output

2021-12-12 Thread Matthias Baesken
On Thu, 9 Dec 2021 08:25:17 GMT, Matthias Baesken wrote: > Please review this small test fix. > KeytoolOpensslInteropTest.java fails with the output below. > Seems on our SUSE Linux 15 (openssl is > ~> openssl version > OpenSSL 1.1.0i-fips 14 Aug 2018 > ) we get a slightly different output with a