Re: RFR JDK-8186098: sun/security/pkcs11/KeyStore/SecretKeysBasic.sh failed due to libnss3 version cannot be parsed

2018-01-24 Thread Weijun Wang
The change looks fine. Thanks Max > On Jan 25, 2018, at 1:52 PM, sha.ji...@oracle.com wrote: > > Hi Max, Xuelei, > Please review this updated patch: > http://cr.openjdk.java.net/~jjiang/8186098/webrev.01/ > Both of your suggestions are addressed. > > Best regards, > John Jiang > > On 24/01/20

Re: RFR JDK-8186098: sun/security/pkcs11/KeyStore/SecretKeysBasic.sh failed due to libnss3 version cannot be parsed

2018-01-24 Thread sha . jiang
Hi Max, Xuelei, Please review this updated patch: http://cr.openjdk.java.net/~jjiang/8186098/webrev.01/ Both of your suggestions are addressed. Best regards, John Jiang On 24/01/2018 12:20, Weijun Wang wrote: On Jan 24, 2018, at 11:28 AM, sha.ji...@oracle.com wrote: Hi Max, On 23/01/2018

RFR 8177398: Exclude dot files ending with .conf from krb5.conf's includedir

2018-01-24 Thread Weijun Wang
Please take a review at http://cr.openjdk.java.net/~weijun/8177398/webrev.00/ Dotfiles will not be included in "includedir" of krb5.conf. Thanks Max

Re: contribute to the OpenJDK security group

2018-01-24 Thread Andrew Haley
On 24/01/18 10:39, Tomas Gustavsson wrote: > Imho the P11 layer always needs attention. To work properly we're > relying on some patches, where parts was recently merged into OpenJDK. > We just started testing the Amazon CloudHSM, and that requires changes > to SunPKCS11 as well to work. Not always

Re: contribute to the OpenJDK security group

2018-01-24 Thread Tomas Gustavsson
Sorry for jumping in :-) Imho the P11 layer always needs attention. To work properly we're relying on some patches, where parts was recently merged into OpenJDK. We just started testing the Amazon CloudHSM, and that requires changes to SunPKCS11 as well to work. Not always bad in SunPKCS11 as som

Re: Update mechanism for the upcoming trust store

2018-01-24 Thread Fotis Loukos
Hello Sean, On 23/01/2018 09:12 μμ, Sean Mullan wrote: > Hi Fotis, > > This is an interesting issue and I agree it is important. From your post > it seems that each implementation has come up with a different mechanism > for solving this problem, which is unfortunate - it would be more ideal > if