On Fri, 6 Feb 2026 01:16:20 GMT, Kirill Shirokov <[email protected]> wrote:

>> Removed FFDHE_6144 and FFHDE_8192 from the default list of TLS named groups, 
>> so now to consider them as candidates in TLS handshake user has to enable 
>> them explicitly (e.g. `-Djdk.tls.namedGroups=ffdhe6144,ffhde8192`)
>> 
>> Tested on Linux x64/aarch64, MacOS aarch64, Windows x64 using jtreg 
>> `test/jdk/sun/security/ssl` and `test/jdk/javax/net/ssl`.
>> 
>> [tests-linux-aarch64.log](https://github.com/user-attachments/files/25080233/tests-linux-aarch64.log)
>> [tests-linux-x86.log](https://github.com/user-attachments/files/25080235/tests-linux-x86.log)
>> [tests-macos-aarch64.log](https://github.com/user-attachments/files/25080236/tests-macos-aarch64.log)
>> [tests-windows-x64.log](https://github.com/user-attachments/files/25080237/tests-windows-x64.log)
>> 
>> - [x] I confirm that I make this contribution in accordance with the 
>> [OpenJDK Interim AI Policy](https://openjdk.org/legal/ai).
>
> Kirill Shirokov has updated the pull request incrementally with one 
> additional commit since the last revision:
> 
>   Added new bug reference to 
> test/jdk/sun/security/ssl/DHKeyExchange/UseStrongDHSizes.java

src/java.base/share/classes/sun/security/ssl/NamedGroup.java line 882:

> 880:                 FFDHE_3072,
> 881:                 FFDHE_4096
> 882:                 // FFDHE_6144 and FFDHE_8192 were removed in JDK-8373426

There is no need to include this comment. You can get this from the source code 
history.

-------------

PR Review Comment: https://git.openjdk.org/jdk/pull/29577#discussion_r3288275204

Reply via email to