On Tue, 15 Sep 2026 22:06:28 GMT, Weijun Wang <[email protected]> wrote:

>> src/java.base/share/classes/sun/security/tools/keytool/Main.java line 1935:
>> 
>>> 1933:                     keysize = 
>>> SecurityProviderConstants.DEF_DSA_KEY_SIZE;
>>> 1934:                 } else if ("EdDSA".equalsIgnoreCase(keyAlgName)) {
>>> 1935:                     keysize = 
>>> SecurityProviderConstants.DEF_ED_KEY_SIZE;
>> 
>> Can we also remove the constants not used here like `DEF_ED_KEY_SIZE` now? 
>> For example, it looks like we can initialize with the Ed25519 
>> `NamedParameterSpec` 
>> [here](https://github.com/openjdk/jdk/blob/d9397cebdb4945dbf10f9d9751fee72781dd89cf/src/java.base/share/classes/sun/security/ec/ed/EdDSAKeyPairGenerator.java#L54)
>>  instead of the key size. That is the only other place it is used.
>
> Yes.
> 
> `DEF_ED_KEY_SIZE` is only used in `EdDSAKeyPairGenerator` which could have 
> been a `NamedParameterSpec`. `DEF_XEC_KEY_SIZE` is not used at all because 
> `XDHKeyPairGenerator` has its own default (a `NamedParameterSpec`) inside. 
> `DEF_EC_KEY_SIZE` is used by both SunEC and SunPKCS11 and is translated to a 
> name using `ECUtil.getECParameterSpec` at a very early stage.
> 
> I suggest we migrate all `DEF_EC_KEY_SIZE`, `DEF_ED_KEY_SIZE` and 
> `DEF_XEC_KEY_SIZE` to names and reference them from our own implementations. 
> When we add PKCS11 implementations on EdDSA and XDH we can use them.
> 
> What do you think? We can create another issue on this change.

I'm fine with doing it in a separate issue.

-------------

PR Review Comment: https://git.openjdk.org/jdk/pull/32616#discussion_r4027316558

Reply via email to