Skip to content

8369282: Distrust TLS server certificates anchored by Chunghwa ePKI Root CA#255

Closed
rm-gh-8 wants to merge 1 commit intoopenjdk:masterfrom
rm-gh-8:JDK-8369282-V25
Closed

8369282: Distrust TLS server certificates anchored by Chunghwa ePKI Root CA#255
rm-gh-8 wants to merge 1 commit intoopenjdk:masterfrom
rm-gh-8:JDK-8369282-V25

Conversation

@rm-gh-8
Copy link
Copy Markdown
Contributor

@rm-gh-8 rm-gh-8 commented Feb 11, 2026

Backporting JDK-8369282: Distrust TLS server certificates anchored by Chunghwa ePKI Root CA.

This PR implements OpenJDK distrust of TLS certificates anchored by Chunghwa Telecom's ePKI Root CA (following Google/Mozilla). Certificates issued after March 17, 2026 will be rejected during TLS handshakes in SunJSSE.

For parity with Oracle JDK.

Ran related tests on linux-x64, linux-aarch64, macos-aarch64 and windows-x64:

make test TEST=test/jdk/sun/security/ssl/X509TrustManagerImpl/distrust/Chunghwa.java

Results attached:

windows-x64-specific-test.log
macos-aarch64-specific-test.log
linux-x64-specific-test.log
linux-aarch64-specific-test.log


Progress

  • Change must not contain extraneous whitespace
  • Commit message must refer to an issue
  • JDK-8369282 needs maintainer approval
  • Change requires CSR request JDK-8374054 to be approved

Issues

  • JDK-8369282: Distrust TLS server certificates anchored by Chunghwa ePKI Root CA (Enhancement - P3 - Approved)
  • JDK-8374054: Distrust TLS server certificates anchored by Chunghwa ePKI Root CA (CSR)

Reviewing

Using git

Checkout this PR locally:
$ git fetch https://git.openjdk.org/jdk25u-dev.git pull/255/head:pull/255
$ git checkout pull/255

Update a local copy of the PR:
$ git checkout pull/255
$ git pull https://git.openjdk.org/jdk25u-dev.git pull/255/head

Using Skara CLI tools

Checkout this PR locally:
$ git pr checkout 255

View PR using the GUI difftool:
$ git pr show -t 255

Using diff file

Download this PR as a diff file:
https://git.openjdk.org/jdk25u-dev/pull/255.diff

Using Webrev

Link to Webrev Comment

@bridgekeeper
Copy link
Copy Markdown

bridgekeeper Bot commented Feb 11, 2026

👋 Welcome back rm-gh-8! A progress list of the required criteria for merging this PR into master will be added to the body of your pull request. There are additional pull request commands available for use with this pull request.

@openjdk
Copy link
Copy Markdown

openjdk Bot commented Feb 11, 2026

@rm-gh-8 This change now passes all automated pre-integration checks.

ℹ️ This project also has non-automated pre-integration requirements. Please see the file CONTRIBUTING.md for details.

After integration, the commit message for the final commit will be:

8369282: Distrust TLS server certificates anchored by Chunghwa ePKI Root CA

You can use pull request commands such as /summary, /contributor and /issue to adjust it as needed.

At the time when this comment was updated there had been 23 new commits pushed to the master branch:

As there are no conflicts, your changes will automatically be rebased on top of these commits when integrating. If you prefer to avoid this automatic rebasing, please check the documentation for the /integrate command for further details.

As you do not have Committer status in this project an existing Committer must agree to sponsor your change.

➡️ To flag this PR as ready for integration with the above commit message, type /integrate in a new comment. (Afterwards, your sponsor types /sponsor in a new comment to perform the integration).

@openjdk openjdk Bot changed the title Backport 92abc6dfe43a2c1f10dcfcf1e197fc9369f70ee3 8369282: Distrust TLS server certificates anchored by Chunghwa ePKI Root CA Feb 11, 2026
@openjdk
Copy link
Copy Markdown

openjdk Bot commented Feb 11, 2026

This backport pull request has now been updated with issue from the original commit.

@openjdk openjdk Bot added backport Port of a pull request already in a different code base clean Identical backport; no merge resolution required labels Feb 11, 2026
@rm-gh-8 rm-gh-8 marked this pull request as ready for review February 11, 2026 18:05
@openjdk
Copy link
Copy Markdown

openjdk Bot commented Feb 11, 2026

⚠️ @rm-gh-8 This change is now ready for you to apply for maintainer approval. This can be done directly in each associated issue or by using the /approval command.

@openjdk openjdk Bot added the rfr Pull request is ready for review label Feb 11, 2026
@mlbridge
Copy link
Copy Markdown

mlbridge Bot commented Feb 11, 2026

Webrevs

@rm-gh-8
Copy link
Copy Markdown
Contributor Author

rm-gh-8 commented Feb 12, 2026

/approval request for backport of JDK-8369282: Distrust TLS server certificates anchored by Chunghwa ePKI Root CA.

This PR implements OpenJDK distrust of TLS certificates anchored by Chunghwa Telecom's ePKI Root CA (following Google/Mozilla). Certificates issued after March 17, 2026 will be rejected during TLS handshakes in SunJSSE.

For parity with Oracle JDK.

High risk - Taiwan/APAC organizations using Chunghwa certificates will face TLS failures after JDK upgrade. Third-party services with affected certificates will break.

@openjdk
Copy link
Copy Markdown

openjdk Bot commented Feb 12, 2026

@rm-gh-8
8369282: The approval request has been created successfully.

@openjdk openjdk Bot added approval Requires approval; will be removed when approval is received ready Pull request is ready to be integrated and removed approval Requires approval; will be removed when approval is received labels Feb 12, 2026
@rm-gh-8
Copy link
Copy Markdown
Contributor Author

rm-gh-8 commented Feb 16, 2026

/integrate

@openjdk openjdk Bot added the sponsor Pull request is ready to be sponsored label Feb 16, 2026
@openjdk
Copy link
Copy Markdown

openjdk Bot commented Feb 16, 2026

@rm-gh-8
Your change (at version 19596d1) is now ready to be sponsored by a Committer.

@phohensee
Copy link
Copy Markdown
Member

/sponsor

@openjdk
Copy link
Copy Markdown

openjdk Bot commented Feb 16, 2026

Going to push as commit 4b02ce9.
Since your change was applied there have been 32 commits pushed to the master branch:

Your commit was automatically rebased without conflicts.

@openjdk openjdk Bot added the integrated Pull request has been integrated label Feb 16, 2026
@openjdk openjdk Bot closed this Feb 16, 2026
@openjdk openjdk Bot removed ready Pull request is ready to be integrated rfr Pull request is ready for review sponsor Pull request is ready to be sponsored labels Feb 16, 2026
@openjdk
Copy link
Copy Markdown

openjdk Bot commented Feb 16, 2026

@phohensee @rm-gh-8 Pushed as commit 4b02ce9.

💡 You may see a message that your pull request was closed with unmerged commits. This can be safely ignored.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport Port of a pull request already in a different code base clean Identical backport; no merge resolution required integrated Pull request has been integrated

Development

Successfully merging this pull request may close these issues.

2 participants