8349583: Add mechanism to disable signature schemes based on their TLS scope #3130
+1,044
−132
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Backport of JDK-8349583 from JDK17, a first step to disable SHA-1 in TLS/DTLS 1.2 handshake signatures to comply with the Oracle JRE Cryptographic Roadmap, to be followed with JDK-8340321.
Backport is not clean, as there're significant changes from JDK17.
To ease review, three additional commits adapt the backport to JDK11, which is missing JDK-8284047 (2nd commit) and JDK-8288209 (3rd commit). Also JDK11 is missing
ByteBuffer.slice(int, int)(4th commit).Tested on Linux with
tier1tests and withrun-test-jdk_security:Progress
Integration blocker
Issues
Reviewing
Using
gitCheckout this PR locally:
$ git fetch https://git.openjdk.org/jdk11u-dev.git pull/3130/head:pull/3130$ git checkout pull/3130Update a local copy of the PR:
$ git checkout pull/3130$ git pull https://git.openjdk.org/jdk11u-dev.git pull/3130/headUsing Skara CLI tools
Checkout this PR locally:
$ git pr checkout 3130View PR using the GUI difftool:
$ git pr show -t 3130Using diff file
Download this PR as a diff file:
https://git.openjdk.org/jdk11u-dev/pull/3130.diff
Using Webrev
Link to Webrev Comment