Re: RFR: 8288985: P11TlsKeyMaterialGenerator works with ChaCha20-Poly1305 [v3]

2022-06-23 Thread zzambers
> TLS `*_CHACHA20_POLY1305_*` cipher suites are currently broken when > configuration with SunPKCS11 provider is used. I discovered this by my > ssl-tests testsuite [1]. > > > make TEST_PKCS11_FIPS=1 > SSLTESTS_SSL_CONFIG_FILTER=SunJSSE,Default,TLSv1.2,TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256

Re: RFR: 8288985: P11TlsKeyMaterialGenerator works with ChaCha20-Poly1305 [v2]

2022-06-23 Thread zzambers
On Thu, 23 Jun 2022 16:47:18 GMT, Valerie Peng wrote: >> zzambers has updated the pull request incrementally with one additional >> commit since the last revision: >> >> TestKeyMaterialChaCha20.java: Added bug number > > src/jdk.crypto.cryptoki/share/classes/sun/security/pkcs11/P11SecretKeyFa

Re: RFR: 8288985: P11TlsKeyMaterialGenerator works with ChaCha20-Poly1305 [v2]

2022-06-23 Thread Valerie Peng
On Wed, 22 Jun 2022 15:59:44 GMT, zzambers wrote: >> TLS `*_CHACHA20_POLY1305_*` cipher suites are currently broken when >> configuration with SunPKCS11 provider is used. I discovered this by my >> ssl-tests testsuite [1]. >> >> >> make TEST_PKCS11_FIPS=1 >> SSLTESTS_SSL_CONFIG_FILTER=SunJSS

Re: RFR: 8288985: P11TlsKeyMaterialGenerator works with ChaCha20-Poly1305 [v2]

2022-06-23 Thread Valerie Peng
On Wed, 22 Jun 2022 15:59:44 GMT, zzambers wrote: >> TLS `*_CHACHA20_POLY1305_*` cipher suites are currently broken when >> configuration with SunPKCS11 provider is used. I discovered this by my >> ssl-tests testsuite [1]. >> >> >> make TEST_PKCS11_FIPS=1 >> SSLTESTS_SSL_CONFIG_FILTER=SunJSS

Re: RFR: 8288985: P11TlsKeyMaterialGenerator works with ChaCha20-Poly1305 [v2]

2022-06-22 Thread zzambers
> TLS `*_CHACHA20_POLY1305_*` cipher suites are currently broken when > configuration with SunPKCS11 provider is used. I discovered this by my > ssl-tests testsuite [1]. > > > make TEST_PKCS11_FIPS=1 > SSLTESTS_SSL_CONFIG_FILTER=SunJSSE,Default,TLSv1.2,TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256

RFR: 8288985: P11TlsKeyMaterialGenerator works with ChaCha20-Poly1305

2022-06-22 Thread zzambers
TLS `*_CHACHA20_POLY1305_*` cipher suites are currently broken when configuration with SunPKCS11 provider is used. I discovered this by my ssl-tests testsuite [1]. make TEST_PKCS11_FIPS=1 SSLTESTS_SSL_CONFIG_FILTER=SunJSSE,Default,TLSv1.2,TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256 SSLTESTS_CUS