Skip to content

8340327: A common framework to support public key algorithms with standard parameter sets#2946

Draft
GoeLin wants to merge 4 commits into
openjdk:masterfrom
GoeLin:gpb_8340327-fix1
Draft

8340327: A common framework to support public key algorithms with standard parameter sets#2946
GoeLin wants to merge 4 commits into
openjdk:masterfrom
GoeLin:gpb_8340327-fix1

Conversation

@GoeLin

@GoeLin GoeLin commented Jun 25, 2026

Copy link
Copy Markdown
Member

This is needed to backport the new Quantum-Resistant [1] algorithms.

Patching the original change to 21 first causes two issues:
It does not apply clean to SignatureUtil as
https://bugs.openjdk.org/browse/JDK-8302233: "HSS/LMS: keytool and jarsigner changes"
is not in 21.
I omit the patch to getDefaultSigAlgForKey() that modifies the
default entry of a switch.
The omitted patch just undoes the change of 8302233 for KEM.
Thus the patch is not necessary in 21 as long as 8302233 is not backported.

Further I had to adapt the @modules in test NamedEdDSA.java.
After 21 ec has been moved into java.base.

Then, the change needs a larger rework as https://bugs.openjdk.org/browse/JDK-8318096: "Introduce AsymmetricKey interface with a getParams method" is not in 21. This has a CSR and has not been backported by Oracle, so I don't want to backport it as prereq change.
Thus I check for the new classes wherever this change uses AsymmetricKey, and reworked some more places. The second commit contains these changes.

I ran the new tests and all tests in test/jdk/sun/security/provider succesfully. It also passes SAP's nightly testing.

AddOn: check one more key. Found this backporting 8342002: "sun/security/tools/keytool/GenKeyPairSigner.java failed due to missing certificate output" on top.

AddOn2: The new quantum resistant keys[1] can be backported on top of this clean. sun/security/provider tests pass. ([2] is needed, too.)

[1]
8298390: Implement JEP 496: Quantum-Resistant Module-Lattice-Based Key Encapsulation Mechanism
8298387: Implement JEP 497: Quantum-Resistant Module-Lattice-Based Digital Signature Algorithm

[2]
8342442: "Static ACVP sample tests", backport pending: 2945



Progress

  • Change must be properly reviewed (1 review required, with at least 1 Reviewer)
  • Change must not contain extraneous whitespace
  • Commit message must refer to an issue
  • JDK-8340327 needs maintainer approval

Issue

  • JDK-8340327: A common framework to support public key algorithms with standard parameter sets (Enhancement - P3)

Reviewing

Using git

Checkout this PR locally:
$ git fetch https://git.openjdk.org/jdk21u-dev.git pull/2946/head:pull/2946
$ git checkout pull/2946

Update a local copy of the PR:
$ git checkout pull/2946
$ git pull https://git.openjdk.org/jdk21u-dev.git pull/2946/head

Using Skara CLI tools

Checkout this PR locally:
$ git pr checkout 2946

View PR using the GUI difftool:
$ git pr show -t 2946

Using diff file

Download this PR as a diff file:
https://git.openjdk.org/jdk21u-dev/pull/2946.diff

@GoeLin GoeLin marked this pull request as draft June 25, 2026 08:00
@bridgekeeper

bridgekeeper Bot commented Jun 25, 2026

Copy link
Copy Markdown

👋 Welcome back goetz! A progress list of the required criteria for merging this PR into master will be added to the body of your pull request. There are additional pull request commands available for use with this pull request.

@openjdk

openjdk Bot commented Jun 25, 2026

Copy link
Copy Markdown

❗ This change is not yet ready to be integrated.
See the Progress checklist in the description for automated requirements.

@openjdk openjdk Bot changed the title backport 3f53d571343792341481f4d15970cdc0bcd76a5e 8340327: A common framework to support public key algorithms with standard parameter sets Jun 25, 2026
@openjdk

openjdk Bot commented Jun 25, 2026

Copy link
Copy Markdown

This backport pull request has now been updated with issue from the original commit.

@openjdk openjdk Bot added the backport Port of a pull request already in a different code base label Jun 25, 2026
@GoeLin GoeLin force-pushed the gpb_8340327-fix1 branch from 6107b6e to a022d1e Compare June 25, 2026 09:44
@GoeLin GoeLin force-pushed the gpb_8340327-fix1 branch from 7e11fbc to 84a52c2 Compare June 25, 2026 12:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport Port of a pull request already in a different code base

Development

Successfully merging this pull request may close these issues.

1 participant