Skip to content

Conversation

@TheMangovnik
Copy link
Contributor

@TheMangovnik TheMangovnik commented Nov 20, 2025

Backport of JDK-8245545 - Disable TLS_RSA cipher suites

Some TLS suites do not preserve forward-secrecy and are not commonly used - and should not be used.

Not clean back port. This includes:

  • Selection of disabled tests and some include that is in jdk11 but not in jdk17.
  • Changed indentation of edited block of string defining disabled cipher suites.
  • Bunch of copyright notices.

Tested on Fedora 43:

  • gtests passed
  • T1 have same fails before and after the back port -> not related to this.
  • jtreg:test/jdk/sun/security passed.
  • jtreg:test/jdk/javax/net/ssl passed.
  • Github Actions passed.

Progress

  • Change must be properly reviewed (1 review required, with at least 1 Reviewer)
  • Change must not contain extraneous whitespace
  • Commit message must refer to an issue
  • JDK-8245545 needs maintainer approval
  • Change requires CSR request JDK-8344257 to be approved

Issues

  • JDK-8245545: Disable TLS_RSA cipher suites (Enhancement - P3)
  • JDK-8344257: Disable TLS_RSA cipher suites (CSR)

Reviewing

Using git

Checkout this PR locally:
$ git fetch https://git.openjdk.org/jdk11u-dev.git pull/3124/head:pull/3124
$ git checkout pull/3124

Update a local copy of the PR:
$ git checkout pull/3124
$ git pull https://git.openjdk.org/jdk11u-dev.git pull/3124/head

Using Skara CLI tools

Checkout this PR locally:
$ git pr checkout 3124

View PR using the GUI difftool:
$ git pr show -t 3124

Using diff file

Download this PR as a diff file:
https://git.openjdk.org/jdk11u-dev/pull/3124.diff

Using Webrev

Link to Webrev Comment

@bridgekeeper
Copy link

bridgekeeper bot commented Nov 20, 2025

👋 Welcome back TheMangovnik! A progress list of the required criteria for merging this PR into pr/3123 will be added to the body of your pull request. There are additional pull request commands available for use with this pull request.

@openjdk
Copy link

openjdk bot commented Nov 20, 2025

❗ This change is not yet ready to be integrated.
See the Progress checklist in the description for automated requirements.

@openjdk openjdk bot changed the title backport b838ae0a7bbe34f345a4d56af21df4badce0caf2 8245545: Disable TLS_RSA cipher suites Nov 20, 2025
@openjdk
Copy link

openjdk bot commented Nov 20, 2025

This backport pull request has now been updated with issue from the original commit.

@openjdk openjdk bot added backport Port of a pull request already in a different code base rfr Pull request is ready for review labels Nov 20, 2025
@mlbridge
Copy link

mlbridge bot commented Nov 20, 2025

Webrevs

@openjdk-notifier openjdk-notifier bot changed the base branch from pr/3123 to master November 26, 2025 09:26
@openjdk-notifier
Copy link

The parent pull request that this pull request depends on has now been integrated and the target branch of this pull request has been updated. This means that changes from the dependent pull request can start to show up as belonging to this pull request, which may be confusing for reviewers. To remedy this situation, simply merge the latest changes from the new target branch into this pull request by running commands similar to these in the local repository for your personal fork:

git checkout backport/JDK-8245545
git fetch https://git.openjdk.org/jdk11u-dev.git master
git merge FETCH_HEAD
# if there are conflicts, follow the instructions given by git merge
git commit -m "Merge master"
git push

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport Port of a pull request already in a different code base rfr Pull request is ready for review

Development

Successfully merging this pull request may close these issues.

1 participant