Removed FFDHE_6144 and FFHDE_8192 from the default list of TLS named groups, so 
now to consider them as candidates in TLS handshake user has to enable them 
explicitly (e.g. `-Djdk.tls.namedGroups=ffdhe6144,ffhde8192`)

Tested on Linux x64/aarch64, MacOS aarch64, Windows x64 using jtreg 
`test/jdk/sun/security/ssl` and `test/jdk/javax/net/ssl`.

[tests-linux-aarch64.log](https://github.com/user-attachments/files/25080233/tests-linux-aarch64.log)
[tests-linux-x86.log](https://github.com/user-attachments/files/25080235/tests-linux-x86.log)
[tests-macos-aarch64.log](https://github.com/user-attachments/files/25080236/tests-macos-aarch64.log)
[tests-windows-x64.log](https://github.com/user-attachments/files/25080237/tests-windows-x64.log)

-------------

Commit messages:
 - 8373426: Remove ffdhe6144 and ffdhe8192 from default list of TLS named groups

Changes: https://git.openjdk.org/jdk/pull/29577/files
  Webrev: https://webrevs.openjdk.org/?repo=jdk&pr=29577&range=00
  Issue: https://bugs.openjdk.org/browse/JDK-8373426
  Stats: 9 lines in 3 files changed: 0 ins; 5 del; 4 mod
  Patch: https://git.openjdk.org/jdk/pull/29577.diff
  Fetch: git fetch https://git.openjdk.org/jdk.git pull/29577/head:pull/29577

PR: https://git.openjdk.org/jdk/pull/29577

Reply via email to