On Fri, 27 Mar 2026 00:29:41 GMT, Weijun Wang <[email protected]> wrote:

> > The CSR is in Draft state. Will its state be changed? In its Specification 
> > section, for new APIs in Cipher and CpherSpi classes, their `@since `can be 
> > changed to `@since 27`.
> 
> Thanks. All updated. I'm waiting for it to be reviewed first. Then I can 
> propose or fast-track it.

The CSR looks good to me. Have one suggestion about "This is already practiced 
in PKCS#11 on HKDF Expand." in the Solution section, which is a link pointing 
to "Section 5.6 HKDF TLS Token" in the "PKCS#11 Profiles Version 3.1" OASIS 
doc. It looks like we could make it more explicitly with one additional 
sentence? Adding one sentence something like "This approach aligns with PKCS#11 
HKDF mechanisms, where CKM_HKDF_DERIVE mechanism returns a key object and 
CKM_HKDF_DATA mechanism returns a raw byte output".

-------------

PR Comment: https://git.openjdk.org/jdk/pull/18409#issuecomment-4140880264

Reply via email to