Update for the following comment:
   http://hg.openjdk.java.net/jdk/sandbox/rev/e5ed96e446ad

This update will be included in the next webrev for further review.

Xuelei

On 6/1/2018 8:59 AM, Xuelei Fan wrote:
 > http://cr.openjdk.java.net/~xuelei/8196584/webrev-full.00

KeyShareExtension.java
----------------------
  346  NamedGroup ng = NamedGroup.valueOf(entry.namedGroupId);
-347  if (ng != null && !SupportedGroups.isActivatable(
+347  if (ng == null || !SupportedGroups.isActivatable(
  348          shc.sslConfig.algorithmConstraints, ng)) {
           ...
  354      continue;
  355  }

'ng' could be null.  Looks like, a "null" ng should be ignored as well.


Xuelei

On 5/25/2018 4:45 PM, Xuelei Fan wrote:
Hi,

I'd like to invite you to review the TLS 1.3 implementation.  I appreciate it if I could have compatibility and specification feedback before May 31, 2018, and implementation feedback before June 7, 2018.

Here is the webrev:
     http://cr.openjdk.java.net/~xuelei/8196584/webrev-full.00

The formal TLS 1.3 specification is not finalized yet, although it had been approved to be a standard.  The implementation is based on the draft version 28:
     https://tools.ietf.org/html/draft-ietf-tls-tls13-28

For the overall description of this enhancement, please refer to JEP 332:
     http://openjdk.java.net/jeps/332

For the compatibility and specification update, please refer to CSR 8202625:
     https://bugs.openjdk.java.net/browse/JDK-8202625

Note that we are using the sandbox for the development right now.  For more information, please refer to Bradford's previous email:

http://mail.openjdk.java.net/pipermail/security-dev/2018-May/017139.html

Thanks & Regards,
Xuelei

Reply via email to