-
Notifications
You must be signed in to change notification settings - Fork 6.2k
8365820: Apply certificate scope constraints to algorithms in "signature_algorithms" extension when "signature_algorithms_cert" extension is not being sent #26887
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: master
Are you sure you want to change the base?
Conversation
…ure_algorithms" extension when "signature_algorithms_cert" extension is not being sent
👋 Welcome back abarashev! A progress list of the required criteria for merging this PR into |
❗ This change is not yet ready to be integrated. |
@artur-oracle The following label will be automatically applied to this pull request:
When this pull request is ready to be reviewed, an "RFR" email will be sent to the corresponding mailing list. If you would like to change these labels, use the /label pull request command. |
Webrevs
|
…algorithms for TLSv1.3" This reverts commit adc236b.
Can a usecase be added for jdk.tls.server.disableExtensions if this option is being considered. |
JDK-8349583 implementation assumes that OpenJDK client always sends "signature_algorithms_cert" extension together with "signature_algorithms" extension. But we didn't account for
jdk.tls.client.disableExtensions
andjdk.tls.server.disableExtensions
system properties which can disable producing "signature_algorithms_cert" extension. This is an issue similar to JDK-8355779 but on the extension producing side.Per TLSv1.3 RFC:
Also making a few cosmetic changes to the existing code.
Progress
Issue
Reviewing
Using
git
Checkout this PR locally:
$ git fetch https://git.openjdk.org/jdk.git pull/26887/head:pull/26887
$ git checkout pull/26887
Update a local copy of the PR:
$ git checkout pull/26887
$ git pull https://git.openjdk.org/jdk.git pull/26887/head
Using Skara CLI tools
Checkout this PR locally:
$ git pr checkout 26887
View PR using the GUI difftool:
$ git pr show -t 26887
Using diff file
Download this PR as a diff file:
https://git.openjdk.org/jdk/pull/26887.diff
Using Webrev
Link to Webrev Comment