8369282: Distrust TLS server certificates anchored by Chunghwa ePKI Root CA#255
8369282: Distrust TLS server certificates anchored by Chunghwa ePKI Root CA#255rm-gh-8 wants to merge 1 commit intoopenjdk:masterfrom
Conversation
|
👋 Welcome back rm-gh-8! A progress list of the required criteria for merging this PR into |
|
@rm-gh-8 This change now passes all automated pre-integration checks. ℹ️ This project also has non-automated pre-integration requirements. Please see the file CONTRIBUTING.md for details. After integration, the commit message for the final commit will be: You can use pull request commands such as /summary, /contributor and /issue to adjust it as needed. At the time when this comment was updated there had been 23 new commits pushed to the
As there are no conflicts, your changes will automatically be rebased on top of these commits when integrating. If you prefer to avoid this automatic rebasing, please check the documentation for the /integrate command for further details. As you do not have Committer status in this project an existing Committer must agree to sponsor your change. ➡️ To flag this PR as ready for integration with the above commit message, type |
|
This backport pull request has now been updated with issue from the original commit. |
|
|
|
/approval request for backport of JDK-8369282: Distrust TLS server certificates anchored by Chunghwa ePKI Root CA. This PR implements OpenJDK distrust of TLS certificates anchored by Chunghwa Telecom's ePKI Root CA (following Google/Mozilla). Certificates issued after March 17, 2026 will be rejected during TLS handshakes in SunJSSE. For parity with Oracle JDK. High risk - Taiwan/APAC organizations using Chunghwa certificates will face TLS failures after JDK upgrade. Third-party services with affected certificates will break. |
|
/integrate |
|
/sponsor |
|
Going to push as commit 4b02ce9.
Your commit was automatically rebased without conflicts. |
|
@phohensee @rm-gh-8 Pushed as commit 4b02ce9. 💡 You may see a message that your pull request was closed with unmerged commits. This can be safely ignored. |
Backporting JDK-8369282: Distrust TLS server certificates anchored by Chunghwa ePKI Root CA.
This PR implements OpenJDK distrust of TLS certificates anchored by Chunghwa Telecom's ePKI Root CA (following Google/Mozilla). Certificates issued after March 17, 2026 will be rejected during TLS handshakes in SunJSSE.
For parity with Oracle JDK.
Ran related tests on linux-x64, linux-aarch64, macos-aarch64 and windows-x64:
make test TEST=test/jdk/sun/security/ssl/X509TrustManagerImpl/distrust/Chunghwa.java
Results attached:
windows-x64-specific-test.log
macos-aarch64-specific-test.log
linux-x64-specific-test.log
linux-aarch64-specific-test.log
Progress
Issues
Reviewing
Using
gitCheckout this PR locally:
$ git fetch https://git.openjdk.org/jdk25u-dev.git pull/255/head:pull/255$ git checkout pull/255Update a local copy of the PR:
$ git checkout pull/255$ git pull https://git.openjdk.org/jdk25u-dev.git pull/255/headUsing Skara CLI tools
Checkout this PR locally:
$ git pr checkout 255View PR using the GUI difftool:
$ git pr show -t 255Using diff file
Download this PR as a diff file:
https://git.openjdk.org/jdk25u-dev/pull/255.diff
Using Webrev
Link to Webrev Comment