On Wed, 30 Sep 2026 13:45:32 GMT, Weijun Wang <[email protected]> wrote:
>> The enhancement implements the new RFC 9846-style support group selection on >> the server side (first mutual group matters) and change the supported-groups >> format. Specifically: >> >> 1. `SSLParameters.setNamedGroups` and the `jdk.tls.namedGroups` system >> property now recognize a *-prefix on a group name. >> 2. The prefix does not change the supported_groups extension. >> 3. On a TLS 1.3 client, usable starred groups determine the initial >> key_share entries. If no usable starred group remains, JSSE falls back to >> its existing automatic key-share selection. >> 4. SunJSSE’s default parameters contains 2 starred groups, which can be >> observed by `getNamedGroups`. >> 5. The server ignores the marker in its own configuration. >> 6. Server group selection now follows RFC 9846: choose the first mutually >> supported group according to the client’s supported_groups order, then sends >> ServerHello if its key share is present or HelloRetryRequest if not. >> >> No new API or system property defined for the new format. The existing >> methods and system property are already called a lot by both JSSE itself and >> an application. The default value of the system property is empty which >> gives each provider the chance to define it itself. >> >> --------- >> - [x] I confirm that I make this contribution in accordance with the >> [OpenJDK Interim AI Policy](https://openjdk.org/legal/ai). > > Weijun Wang has updated the pull request with a new target base due to a > merge or a rebase. The incremental webrev excludes the unrelated changes > brought in by the merge/rebase. The pull request contains four additional > commits since the last revision: > > - Merge branch 'master' into 8388484 > - an example and a more precise spec > - a test > - the change src/java.base/share/classes/javax/net/ssl/SSLParameters.java line 872: > 870: * returns the default named groups for connection populated objects, > 871: * or {@code null} for pre-populated objects. Any prefixed asterisk > 872: * is retained. I think you need to explain the asterisk syntax in this method as well as `setNamedGroups`. If I just call `SSLSocket.getSSLParameters().getNamedGroups()` it will return the provider defaults with asterisks, assuming the provider supports it. Maybe you can add a common section somewhere and link to it. I also think we need an implementation note in both methods with something like "The JDK SunJSSE provider supports the asterisk syntax. Other providers may not." ------------- PR Review Comment: https://git.openjdk.org/jdk/pull/32586#discussion_r4168930604
