This looks fine. However, the bug report never mentions why it is ok to remove the CKM_SSL3_KEY_AND_MAC_DERIVE and CKM_TLS_KEY_AND_MAC_DERIVE mechanisms. I think it should be updated.

Also, isn't this the kind of thing we should periodically review each release? If so, maybe we should create a sub-CR for JDK 8, keep that open, and re-evaluate later.

--Sean

On 4/28/11 8:59 PM, Valerie (Yu-Ching) Peng wrote:
Sean,

Could you please review this PKCS11 configuration file change before next 
Monday?

http://cr.openjdk.java.net/~valeriep/7036252/webrev.00/

I have run the regression tests against the new config file and things look 
fine.
More information can be found in the bugster record.

Thanks,
Valerie

Reply via email to