8387124: Incomplete algorithm decomposition for TLS 1.3 cipher suites in SSLAlgorithmDecomposer - #679
Conversation
|
👋 Welcome back achmielewski! A progress list of the required criteria for merging this PR into |
|
❗ This change is not yet ready to be integrated. |
|
This backport pull request has now been updated with issue from the original commit. |
|
/approval request The change applies cleanly, I would classify the backport risk as low, with the main risk being behavioral compatibility. The issue addresses incomplete decomposition of TLS 1.3 cipher suites, which caused jdk.tls.disabledAlgorithms constraints such as AES_128_GCM, AES_256_GCM, and CHACHA20_POLY1305 to not consistently match the corresponding TLS cipher suites. As a result, disabling these algorithms may not disable the corresponding TLS 1.3 cipher suites as expected. This change makes the behavior consistent with other cipher suites and ensures that the configured algorithm constraints are applied correctly. Please note that this change will be followed by JDK-8387874, which improves the timeout handling in this test. |
|
|
|
@chmielewskiandreas |
Hi, this is a clean backport of 3f52251c9d82991b14f0bbf34c81627911b0fdbf
Testing:
make run-test TEST="jdk_security"
make run-test TEST="test/jdk/javax/net/ssl/ciphersuites/BulkCipherDisabledAlgorithms.java
test/jdk/sun/security/ssl/CipherSuite/TLS13BulkCipherDisabledCipherSuite.java"
Progress
Issue
Reviewing
Using
gitCheckout this PR locally:
$ git fetch https://git.openjdk.org/jdk25u-dev.git pull/679/head:pull/679$ git checkout pull/679Update a local copy of the PR:
$ git checkout pull/679$ git pull https://git.openjdk.org/jdk25u-dev.git pull/679/headUsing Skara CLI tools
Checkout this PR locally:
$ git pr checkout 679View PR using the GUI difftool:
$ git pr show -t 679Using diff file
Download this PR as a diff file:
https://git.openjdk.org/jdk25u-dev/pull/679.diff
Using Webrev
Link to Webrev Comment