Skip to content

Conversation

@JinhangZhang
Copy link
Collaborator

@JinhangZhang JinhangZhang commented Nov 7, 2025

According to the policy, curve size less than 192 should not be allowed in computing shared secret in ECDH
keyagreement in FIPS 140-3 mode. This PR proposes an option to enable/disable this behaviour.

Backported-from: #826

Signed-off-by: JinhangZhang [email protected]

According to the policy, curve size less than 192 should
not be allowed in computing shared secret in ECDH
keyagreement in FIPS 140-3 mode. This PR proposes an option
to enable/disable this behaviour.

Signed-off-by: JinhangZhang <[email protected]>
Copy link
Member

@jasonkatonica jasonkatonica left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Copy link
Member

@KostasTsiounis KostasTsiounis left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@jasonkatonica jasonkatonica merged commit 7883ff9 into IBM:java21 Nov 10, 2025
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants