8387124: Incomplete algorithm decomposition for TLS 1.3 cipher suites in SSLAlgorithmDecomposer - #13
Conversation
|
👋 Welcome back achmielewski! A progress list of the required criteria for merging this PR into |
|
/template append |
|
@chmielewskiandreas This change now passes all automated pre-integration checks. ℹ️ This project also has non-automated pre-integration requirements. Please see the file CONTRIBUTING.md for details. After integration, the commit message for the final commit will be: You can use pull request commands such as /summary, /contributor and /issue to adjust it as needed. At the time when this comment was updated there had been 72 new commits pushed to the
As there are no conflicts, your changes will automatically be rebased on top of these commits when integrating. If you prefer to avoid this automatic rebasing, please check the documentation for the /integrate command for further details. As you do not have Committer status in this project an existing Committer must agree to sponsor your change. ➡️ To flag this PR as ready for integration with the above commit message, type |
|
This backport pull request has now been updated with issue from the original commit. |
|
@chmielewskiandreas The pull request template has been appended to the pull request body |
|
/approval request I am proposing this clean backport. I would classify the backport risk as low, with the main risk being behavioral compatibility. The issue addresses incomplete decomposition of TLS 1.3 cipher suites, which caused jdk.tls.disabledAlgorithms constraints such as AES_128_GCM, AES_256_GCM, and CHACHA20_POLY1305 to not consistently match the corresponding TLS cipher suites. As a result, disabling these algorithms may not disable the corresponding TLS 1.3 cipher suites as expected. This change makes the behavior consistent with other cipher suites and ensures that the configured algorithm constraints are applied correctly. |
|
|
|
@chmielewskiandreas |
Webrevs
|
|
/approval request cancel |
|
@chmielewskiandreas |
Reviewed-by: abarashev, mullan
|
/approval request The change applies cleanly, although it is not marked as a clean backport. It consists of:
I would classify the backport risk as low, with the main risk being behavioral compatibility. The issue addresses incomplete decomposition of TLS 1.3 cipher suites, which caused jdk.tls.disabledAlgorithms constraints such as AES_128_GCM, AES_256_GCM, and CHACHA20_POLY1305 to not consistently match the corresponding TLS cipher suites. As a result, disabling these algorithms may not disable the corresponding TLS 1.3 cipher suites as expected. This change makes the behavior consistent with other cipher suites and ensures that the configured algorithm constraints are applied correctly. |
|
@chmielewskiandreas |
|
HI @chmielewskiandreas |
@GoeLin : The fix and the follow-up test fix is combined within this PR. I think it does not make sense to have two backports for the same issue. |
|
HI @chmielewskiandreas |
This reverts commit 91bc1e7.
ok, that is also fine for me |
|
/approval request The change applies cleanly, I would classify the backport risk as low, with the main risk being behavioral compatibility. The issue addresses incomplete decomposition of TLS 1.3 cipher suites, which caused jdk.tls.disabledAlgorithms constraints such as AES_128_GCM, AES_256_GCM, and CHACHA20_POLY1305 to not consistently match the corresponding TLS cipher suites. As a result, disabling these algorithms may not disable the corresponding TLS 1.3 cipher suites as expected. This change makes the behavior consistent with other cipher suites and ensures that the configured algorithm constraints are applied correctly. Please note that this change will be followed by JDK-8387874, which improves the timeout handling in this test. |
|
@chmielewskiandreas |
Hi, this is a clean backport of 3f52251
Testing:
make run-test TEST="jdk_security"
make run-test TEST="test/jdk/javax/net/ssl/ciphersuites/BulkCipherDisabledAlgorithms.java test/jdk/sun/security/ssl/CipherSuite/TLS13BulkCipherDisabledCipherSuite.java"
Progress
Issue
Reviewing
Using
gitCheckout this PR locally:
$ git fetch https://git.openjdk.org/jdk27u.git pull/13/head:pull/13$ git checkout pull/13Update a local copy of the PR:
$ git checkout pull/13$ git pull https://git.openjdk.org/jdk27u.git pull/13/headUsing Skara CLI tools
Checkout this PR locally:
$ git pr checkout 13View PR using the GUI difftool:
$ git pr show -t 13Using diff file
Download this PR as a diff file:
https://git.openjdk.org/jdk27u/pull/13.diff
Using Webrev
Link to Webrev Comment