-
Notifications
You must be signed in to change notification settings - Fork 5.8k
8347596: Update HSS/LMS public key encoding #23083
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
👋 Welcome back weijun! A progress list of the required criteria for merging this PR into |
@wangweij This change now passes all automated pre-integration checks. ℹ️ This project also has non-automated pre-integration requirements. Please see the file CONTRIBUTING.md for details. After integration, the commit message for the final commit will be:
You can use pull request commands such as /summary, /contributor and /issue to adjust it as needed. At the time when this comment was updated there had been 38 new commits pushed to the
As there are no conflicts, your changes will automatically be rebased on top of these commits when integrating. If you prefer to avoid this automatic rebasing, please check the documentation for the /integrate command for further details. ➡️ To integrate this PR with the above commit message to the |
Webrevs
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Does this interoperate with BC?
@@ -783,11 +779,18 @@ public String toString() { | |||
@Override | |||
protected void parseKeyBits() throws InvalidKeyException { | |||
byte[] keyArray = getKey().toByteArray(); | |||
if ((keyArray[0] != DerValue.tag_OctetString) || (keyArray[1] != keyArray.length -2)) { | |||
throw new InvalidKeyException("Bad X509Key"); | |||
// Check less than minimum length to make sure this method works as expected |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
s/Check less/Check if less/
or just delete the comment since it adds no useful information
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
OK. My intent was to say this check is not final (because minimal length of an HSS/LMS public key is more than 12) but it is still necessary to prevent OOIBE in this method. I can see it is not very useful.
} | ||
if (keyArray[0] == DerValue.tag_OctetString | ||
&& keyArray[1] == keyArray.length - 2) { | ||
// pre-8347596 format that has an inner OCTET STRING. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I think I would delete the "pre-8347596 format" part of the comment.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Why? Curious people can further check out what happened from here.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Maybe it's a Solaris thing where bug IDs in the code was frowned upon.
It will, once BC 1.80 is out. |
/integrate |
Going to push as commit 0ee6ba9.
Your commit was automatically rebased without conflicts. |
/backport :jdk24 |
@wangweij the backport was successfully created on the branch backport-wangweij-0ee6ba9c-jdk24 in my personal fork of openjdk/jdk. To create a pull request with this backport targeting openjdk/jdk:jdk24, just click the following link: The title of the pull request is automatically filled in correctly and below you find a suggestion for the pull request body:
If you need to update the source branch of the pull then run the following commands in a local clone of your personal fork of openjdk/jdk:
|
Update the encoding of HSS/LMS public key to be consistent with https://www.rfc-editor.org/rfc/rfc9708.html#name-changes-since-rfc-8708 and https://datatracker.ietf.org/doc/html/draft-ietf-lamps-x509-shbs-13#name-hss-public-keys.
Progress
Issue
Reviewers
Reviewing
Using
git
Checkout this PR locally:
$ git fetch https://git.openjdk.org/jdk.git pull/23083/head:pull/23083
$ git checkout pull/23083
Update a local copy of the PR:
$ git checkout pull/23083
$ git pull https://git.openjdk.org/jdk.git pull/23083/head
Using Skara CLI tools
Checkout this PR locally:
$ git pr checkout 23083
View PR using the GUI difftool:
$ git pr show -t 23083
Using diff file
Download this PR as a diff file:
https://git.openjdk.org/jdk/pull/23083.diff
Using Webrev
Link to Webrev Comment