# HG changeset patch # User xuelei # Date 1477612178 0 # Node ID 07e906f1a20bb0b0ed79d6654eb29d0d8d717348 # Parent b3da085a9846b52d12136e0f3cba5cb309956fc0 8168822: Document that algorithm restrictions do not apply to trusted anchors Reviewed-by: weijun, jnimeh, mullan diff -r b3da085a9846 -r 07e906f1a20b jdk/src/java.base/share/conf/security/java.security --- a/jdk/src/java.base/share/conf/security/java.security Thu Oct 27 21:22:57 2016 +0000 +++ b/jdk/src/java.base/share/conf/security/java.security Thu Oct 27 23:49:38 2016 +0000 @@ -645,6 +645,9 @@ # before larger keysize constraints of the same algorithm. For example: # "RSA keySize < 1024 & jdkCA, RSA keySize < 2048". # +# Note: The algorithm restrictions do not apply to trust anchors or +# self-signed certificates. +# # Note: This property is currently used by Oracle's PKIX implementation. It # is not guaranteed to be examined and used by other implementations. # @@ -714,6 +717,9 @@ # See the specification of "jdk.certpath.disabledAlgorithms" for the # syntax of the disabled algorithm string. # +# Note: The algorithm restrictions do not apply to trust anchors or +# self-signed certificates. +# # Note: This property is currently used by Oracle's JSSE implementation. # It is not guaranteed to be examined and used by other implementations. #