On Wed, 4 Feb 2026 19:29:02 GMT, Kirill Shirokov <[email protected]> wrote:
> Removed FFDHE_6144 and FFHDE_8192 from the default list of TLS named groups, > so now to consider them as candidates in TLS handshake user has to enable > them explicitly (e.g. `-Djdk.tls.namedGroups=ffdhe6144,ffhde8192`) > > Tested on Linux x64/aarch64, MacOS aarch64, Windows x64 using jtreg > `test/jdk/sun/security/ssl` and `test/jdk/javax/net/ssl`. > > [tests-linux-aarch64.log](https://github.com/user-attachments/files/25080233/tests-linux-aarch64.log) > [tests-linux-x86.log](https://github.com/user-attachments/files/25080235/tests-linux-x86.log) > [tests-macos-aarch64.log](https://github.com/user-attachments/files/25080236/tests-macos-aarch64.log) > [tests-windows-x64.log](https://github.com/user-attachments/files/25080237/tests-windows-x64.log) > > - [x] I confirm that I make this contribution in accordance with the [OpenJDK > Interim AI Policy](https://openjdk.org/legal/ai). This pull request has now been integrated. Changeset: 2d97d4e7 Author: Kirill Shirokov <[email protected]> Committer: Sean Mullan <[email protected]> URL: https://git.openjdk.org/jdk/commit/2d97d4e7f810ddddd9e2fcb61685042db40e23ce Stats: 10 lines in 3 files changed: 0 ins; 6 del; 4 mod 8373426: Remove ffdhe6144 and ffdhe8192 from default list of TLS named groups Reviewed-by: mullan, jnimeh ------------- PR: https://git.openjdk.org/jdk/pull/29577
