Skip to content

8368694: PKCS11-NSS generic keys generated by DH have leading zeroes stripped - #670

Open
rm-gh-8 wants to merge 1 commit into
openjdk:masterfrom
rm-gh-8:JDK-8368694-V25
Open

8368694: PKCS11-NSS generic keys generated by DH have leading zeroes stripped#670
rm-gh-8 wants to merge 1 commit into
openjdk:masterfrom
rm-gh-8:JDK-8368694-V25

Conversation

@rm-gh-8

@rm-gh-8 rm-gh-8 commented Jul 16, 2026

Copy link
Copy Markdown
Contributor

Backporting JDK-8368694: PKCS11-NSS generic keys generated by DH have leading zeroes stripped.

This PR fixes PKCS11 DH key agreement to preserve leading zero bytes in shared secrets.

For parity with Oracle JDK.

Ran related tests on linux-x64, linux-aarch64, macos-aarch64 and windows-x64:

make test TEST=test/jdk/sun/security/pkcs11
make test TEST=test/jdk/com/sun/crypto/provider/TLS

Results:

windows-x64-specific-test.log
windows-x64-specific-2-test.log
macos-aarch64-specific-test.log
macos-aarch64-specific-2-test.log
linux-x64-specific-test.log
linux-x64-specific-2-test.log
linux-aarch64-specific-test.log
linux-aarch64-specific-2-test.log



Progress

  • Change must not contain extraneous whitespace
  • Commit message must refer to an issue
  • JDK-8368694 needs maintainer approval

Issue

  • JDK-8368694: PKCS11-NSS generic keys generated by DH have leading zeroes stripped (Bug - P4 - Approved)

Reviewing

Using git

Checkout this PR locally:
$ git fetch https://git.openjdk.org/jdk25u-dev.git pull/670/head:pull/670
$ git checkout pull/670

Update a local copy of the PR:
$ git checkout pull/670
$ git pull https://git.openjdk.org/jdk25u-dev.git pull/670/head

Using Skara CLI tools

Checkout this PR locally:
$ git pr checkout 670

View PR using the GUI difftool:
$ git pr show -t 670

Using diff file

Download this PR as a diff file:
https://git.openjdk.org/jdk25u-dev/pull/670.diff

Using Webrev

Link to Webrev Comment

@rm-gh-8
rm-gh-8 marked this pull request as ready for review July 16, 2026 17:47
@bridgekeeper

bridgekeeper Bot commented Jul 16, 2026

Copy link
Copy Markdown

👋 Welcome back rmesde! A progress list of the required criteria for merging this PR into master will be added to the body of your pull request. There are additional pull request commands available for use with this pull request.

@openjdk

openjdk Bot commented Jul 16, 2026

Copy link
Copy Markdown

@rm-gh-8 This change now passes all automated pre-integration checks.

ℹ️ This project also has non-automated pre-integration requirements. Please see the file CONTRIBUTING.md for details.

After integration, the commit message for the final commit will be:

8368694: PKCS11-NSS generic keys generated by DH have leading zeroes stripped

You can use pull request commands such as /summary, /contributor and /issue to adjust it as needed.

At the time when this comment was updated there had been 24 new commits pushed to the master branch:

As there are no conflicts, your changes will automatically be rebased on top of these commits when integrating. If you prefer to avoid this automatic rebasing, please check the documentation for the /integrate command for further details.

➡️ To integrate this PR with the above commit message to the master branch, type /integrate in a new comment.

@openjdk openjdk Bot changed the title Backport 914b44e277df23418736eb00c022bbd829d64e11 8368694: PKCS11-NSS generic keys generated by DH have leading zeroes stripped Jul 16, 2026
@openjdk

openjdk Bot commented Jul 16, 2026

Copy link
Copy Markdown

This backport pull request has now been updated with issue from the original commit.

@openjdk openjdk Bot added backport Port of a pull request already in a different code base clean Identical backport; no merge resolution required labels Jul 16, 2026
@openjdk

openjdk Bot commented Jul 16, 2026

Copy link
Copy Markdown

⚠️ @rm-gh-8 This change is now ready for you to apply for maintainer approval. This can be done directly in each associated issue or by using the /approval command.

@openjdk openjdk Bot added the rfr Pull request is ready for review label Jul 16, 2026
@mlbridge

mlbridge Bot commented Jul 16, 2026

Copy link
Copy Markdown

Webrevs

@rm-gh-8

rm-gh-8 commented Jul 17, 2026

Copy link
Copy Markdown
Contributor Author

/approval request for backport of JDK-8368694: PKCS11-NSS generic keys generated by DH have leading zeroes stripped.

This PR fixes PKCS11 DH key agreement to preserve leading zero bytes in shared secrets.

For parity with Oracle JDK.

Low Risk — non-conforming PKCS11 tokens that ignore the requested secret length will now throw instead of silently recovering.

@openjdk

openjdk Bot commented Jul 17, 2026

Copy link
Copy Markdown

@rm-gh-8
8368694: The approval request has been created successfully.

@openjdk openjdk Bot added approval Requires approval; will be removed when approval is received ready Pull request is ready to be integrated and removed approval Requires approval; will be removed when approval is received labels Jul 17, 2026
@GoeLin

GoeLin commented Jul 28, 2026

Copy link
Copy Markdown
Member

Hi @rm-gh-8
If you push what I have approved, I will approve more.
Or is there a reason not to push these without the pending ones?
Thanks, Goetz.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport Port of a pull request already in a different code base clean Identical backport; no merge resolution required ready Pull request is ready to be integrated rfr Pull request is ready for review

Development

Successfully merging this pull request may close these issues.

2 participants