On Fri, 27 Mar 2026 00:29:41 GMT, Weijun Wang <[email protected]> wrote:
> > The CSR is in Draft state. Will its state be changed? In its Specification > > section, for new APIs in Cipher and CpherSpi classes, their `@since `can be > > changed to `@since 27`. > > Thanks. All updated. I'm waiting for it to be reviewed first. Then I can > propose or fast-track it. The CSR looks good to me. Have one suggestion about "This is already practiced in PKCS#11 on HKDF Expand." in the Solution section, which is a link pointing to "Section 5.6 HKDF TLS Token" in the "PKCS#11 Profiles Version 3.1" OASIS doc. It looks like we could make it more explicitly with one additional sentence? Adding one sentence something like "This approach aligns with PKCS#11 HKDF mechanisms, where CKM_HKDF_DERIVE mechanism returns a key object and CKM_HKDF_DATA mechanism returns a raw byte output". ------------- PR Comment: https://git.openjdk.org/jdk/pull/18409#issuecomment-4140880264
