-
Notifications
You must be signed in to change notification settings - Fork 6.2k
8189441: Define algorithm names for keys derived from KeyAgreement #22650
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
|
👋 Welcome back weijun! A progress list of the required criteria for merging this PR into |
|
@wangweij This change now passes all automated pre-integration checks. ℹ️ This project also has non-automated pre-integration requirements. Please see the file CONTRIBUTING.md for details. After integration, the commit message for the final commit will be: You can use pull request commands such as /summary, /contributor and /issue to adjust it as needed. At the time when this comment was updated there had been 275 new commits pushed to the
As there are no conflicts, your changes will automatically be rebased on top of these commits when integrating. If you prefer to avoid this automatic rebasing, please check the documentation for the /integrate command for further details. ➡️ To integrate this PR with the above commit message to the |
Webrevs
|
|
The comparison of algorithm names was inconsistent, sometimes |
|
Mailing list message from Michael StJohns on security-dev: I ran into a few problems related to a similar approach in my own code.? If this is actually a master secret - maybe 1.3.112.4.30.1283 makes the I ended up with three "generic" secret keys: 1) A generic key - output of a key agreement - can be coerced into any None of these are easy to store in a key store... :-( Later, Mike On 12/18/2024 5:33 PM, Weijun Wang wrote: |
src/java.base/share/classes/com/sun/crypto/provider/DHKeyAgreement.java
Outdated
Show resolved
Hide resolved
|
Can you also replace the link in |
OK, and maybe more. I just found |
|
I've modified too many files and I think they should belong to https://bugs.openjdk.org/browse/JDK-8346736. We should only touch KEM and KeyAgreement here. |
Makes sense. |
|
I've reverted all changes not related to |
src/java.base/share/classes/sun/security/ec/ECDHKeyAgreement.java
Outdated
Show resolved
Hide resolved
seanjmullan
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
A few more minor comments.
src/java.base/share/classes/sun/security/ec/XDHKeyAgreement.java
Outdated
Show resolved
Hide resolved
src/jdk.crypto.cryptoki/share/classes/sun/security/pkcs11/P11KeyAgreement.java
Outdated
Show resolved
Hide resolved
|
/integrate |
|
Going to push as commit aba60a9.
Your commit was automatically rebased without conflicts. |
Allow
Genericas an algorithm in theKeyAgreement::generateSecret(alg)method.Progress
Issues
Reviewers
Reviewing
Using
gitCheckout this PR locally:
$ git fetch https://git.openjdk.org/jdk.git pull/22650/head:pull/22650$ git checkout pull/22650Update a local copy of the PR:
$ git checkout pull/22650$ git pull https://git.openjdk.org/jdk.git pull/22650/headUsing Skara CLI tools
Checkout this PR locally:
$ git pr checkout 22650View PR using the GUI difftool:
$ git pr show -t 22650Using diff file
Download this PR as a diff file:
https://git.openjdk.org/jdk/pull/22650.diff
Using Webrev
Link to Webrev Comment