On Wed, 30 Sep 2026 13:45:32 GMT, Weijun Wang <[email protected]> wrote:

>> The enhancement implements the new RFC 9846-style support group selection on 
>> the server side (first mutual group matters) and change the supported-groups 
>> format. Specifically:
>> 
>> 1. `SSLParameters.setNamedGroups` and the `jdk.tls.namedGroups` system 
>> property now recognize a *-prefix on a group name.
>> 2. The prefix does not change the supported_groups extension.
>> 3. On a TLS 1.3 client, usable starred groups determine the initial 
>> key_share entries. If no usable starred group remains, JSSE falls back to 
>> its existing automatic key-share selection.
>> 4. SunJSSE’s default parameters contains 2 starred groups, which can be 
>> observed by `getNamedGroups`.
>> 5. The server ignores the marker in its own configuration.
>> 6. Server group selection now follows RFC 9846: choose the first mutually 
>> supported group according to the client’s supported_groups order, then sends 
>> ServerHello if its key share is present or HelloRetryRequest if not.
>> 
>> No new API or system property defined for the new format. The existing 
>> methods and system property are already called a lot by both JSSE itself and 
>> an application. The default value of the system property is empty which 
>> gives each provider the chance to define it itself.
>> 
>> ---------
>> - [x] I confirm that I make this contribution in accordance with the 
>> [OpenJDK Interim AI Policy](https://openjdk.org/legal/ai).
>
> Weijun Wang has updated the pull request with a new target base due to a 
> merge or a rebase. The incremental webrev excludes the unrelated changes 
> brought in by the merge/rebase. The pull request contains four additional 
> commits since the last revision:
> 
>  - Merge branch 'master' into 8388484
>  - an example and a more precise spec
>  - a test
>  - the change

src/java.base/share/classes/javax/net/ssl/SSLParameters.java line 872:

> 870:      * returns the default named groups for connection populated objects,
> 871:      * or {@code null} for pre-populated objects. Any prefixed asterisk
> 872:      * is retained.

I think you need to explain the asterisk syntax in this method as well as 
`setNamedGroups`. If I just call 
`SSLSocket.getSSLParameters().getNamedGroups()` it will return the provider 
defaults with asterisks, assuming the provider supports it. Maybe you can add a 
common section somewhere and link to it.

I also think we need an implementation note in both methods with something like 
"The JDK SunJSSE provider supports the asterisk syntax. Other providers may 
not."

-------------

PR Review Comment: https://git.openjdk.org/jdk/pull/32586#discussion_r4168930604

Reply via email to