Re: RFR CSR for 8200400 Restrict Sasl mechanisms

2019-04-18 Thread Weijun Wang
> On Apr 19, 2019, at 8:40 AM, Valerie Peng wrote: > > > The CSR looks fine but some text got truncated and does not show up > completely which may be confusing. Should the lines be made shorter so no > truncation happen? I'll wrap the @systemProperty line in the src. New lines java.securi

Re: RFR CSR for 8200400 Restrict Sasl mechanisms

2019-04-18 Thread Valerie Peng
The CSR looks fine but some text got truncated and does not show up completely which may be confusing. Should the lines be made shorter so no truncation happen? As for returning null silently, at least the current javadoc did state that null is being returned if none can be produced with th

Re: RFR 8221271: sun/security/pkcs11/tls/tls12/TestTLS12.java test failed

2019-04-18 Thread Xuelei Fan
Hi Martin, Good catch of the bug! Looks fine to me. Thanks, Xuelei On 4/18/2019 10:13 AM, Martin Balao wrote: Hi Xuelei, Can I have a review for 8221271 [1]? Webrev.00: * http://cr.openjdk.java.net/~mbalao/webrevs/8221271/8221271.webrev.00/ I'm proposing the following changes: * RSAC

RFR 8221271: sun/security/pkcs11/tls/tls12/TestTLS12.java test failed

2019-04-18 Thread Martin Balao
Hi Xuelei, Can I have a review for 8221271 [1]? Webrev.00: * http://cr.openjdk.java.net/~mbalao/webrevs/8221271/8221271.webrev.00/ I'm proposing the following changes: * RSACipher.java * Minor bug that is triggered only when "key" is not a RSAPublicKey or a RSAPrivateKey (i.e.: it can be a

Re: Refresh cacert File?

2019-04-18 Thread Bernd Eckenfels
Hello, Yes I would have expected the RH „upstream“ builds to have an empty cacerts file as they are described to be „pristine“. However thanks for the pointer that this is not entirely the case. So 8u cacerts is still empty, which is I guess better than outdated. I would consider the content o

Re: Refresh cacert File?

2019-04-18 Thread Severin Gehwolf
Hi, On Wed, 2019-04-17 at 22:43 +, Bernd Eckenfels wrote: > hello, > > I think it was discussed on security-dev before but did not result in > some action as far as I understand it. Currently the „cacert“ file > shipped with 8u upstream builds is a bit outdated. It contains > multiple expire