Uploaded image for project: 'OpenJDK'
  1. OpenJDK
  2. OPENJDK-4108

TLSv1.2 does not support EMS which is required in FIPS enabled RHEL

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Major Major
    • None
    • None
    • FIPS
    • None
    • False
    • Hide

      None

      Show
      None
    • False

      In FIPS enabled RHEL 10, the TLSv1.2 requires extended master secret extension (EMS). Even with Java 21, this extension is not being sent back to the client (Firefox in my test). It ends up with SSL_ERROR_MISSING_EXTENDED_MASTER_SECRET.

      TLSv1.3 works without issues, since EMS is not required for it IIUC.

              mbalaoal Martin Balao
              dvilkola@redhat.com Diana Krepinska
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated: