# HG changeset patch # User Andrew John Hughes # Date 1571884204 -3600 # Node ID eb7ebc35656bf2a91cf98abd0dadaa9c9219e9ef # Parent 469958c06626526bb7822f04fa8c2ec9a8f54a9b PR3755: Update patch against 13.0.1 & JDK-8228825 2019-10-23 Andrew John Hughes PR3755: Update patch against 13.0.1 & JDK-8228825 * AUTHORS: Add Petra Mikova. 2019-10-21 Petra Mikova PR3755: Update patch against 13.0.1 & JDK-8228825 * patches/pr3755.patch: Curves supported over SSL are now limited upstream, as a result of CVE-2019-2894. diff -r 469958c06626 -r eb7ebc35656b AUTHORS --- a/AUTHORS Mon Oct 07 17:07:29 2019 +0100 +++ b/AUTHORS Thu Oct 24 03:30:04 2019 +0100 @@ -25,6 +25,7 @@ DJ Lucas Omair Majid Casey Marshall +Petra Mikova Dan Munckton Raif Naffah Parag Nemade diff -r 469958c06626 -r eb7ebc35656b ChangeLog --- a/ChangeLog Mon Oct 07 17:07:29 2019 +0100 +++ b/ChangeLog Thu Oct 24 03:30:04 2019 +0100 @@ -1,3 +1,15 @@ +2019-10-23 Andrew John Hughes + + PR3755: Update patch against 13.0.1 & JDK-8228825 + * AUTHORS: Add Petra Mikova. + +2019-10-21 Petra Mikova + + PR3755: Update patch against 13.0.1 & JDK-8228825 + * patches/pr3755.patch: + Curves supported over SSL are now limited upstream, + as a result of CVE-2019-2894. + 2019-10-07 Andrew John Hughes PR3755: Support secp256k1 in the default set of curves diff -r 469958c06626 -r eb7ebc35656b patches/pr3755.patch --- a/patches/pr3755.patch Mon Oct 07 17:07:29 2019 +0100 +++ b/patches/pr3755.patch Thu Oct 24 03:30:04 2019 +0100 @@ -126,24 +126,6 @@ final int id; // hash + signature final NamedGroupType type; // group type -diff --git a/src/java.base/share/classes/sun/security/ssl/SupportedGroupsExtension.java b/src/java.base/share/classes/sun/security/ssl/SupportedGroupsExtension.java ---- a/src/java.base/share/classes/sun/security/ssl/SupportedGroupsExtension.java -+++ b/src/java.base/share/classes/sun/security/ssl/SupportedGroupsExtension.java -@@ -214,14 +214,6 @@ - // Secondary XDH curves - NamedGroup.X448, - -- // Secondary NIST curves -- NamedGroup.SECT283_K1, -- NamedGroup.SECT283_R1, -- NamedGroup.SECT409_K1, -- NamedGroup.SECT409_R1, -- NamedGroup.SECT571_K1, -- NamedGroup.SECT571_R1, -- - // non-NIST curves - NamedGroup.SECP256_K1, - diff --git a/src/java.base/share/classes/sun/security/util/CurveDB.java b/src/java.base/share/classes/sun/security/util/CurveDB.java --- a/src/java.base/share/classes/sun/security/util/CurveDB.java +++ b/src/java.base/share/classes/sun/security/util/CurveDB.java