8176503: Disable SHA-1 TLS Server Certificates
authormullan
Tue, 14 Mar 2017 08:35:03 -0400
changeset 44249 0462723a58ef
parent 44247 b128e61f230e
child 44250 af577b8d7b2f
8176503: Disable SHA-1 TLS Server Certificates Reviewed-by: vinnie, ascarpino
jdk/src/java.base/share/conf/security/java.security
--- a/jdk/src/java.base/share/conf/security/java.security	Mon Mar 13 13:38:14 2017 -0700
+++ b/jdk/src/java.base/share/conf/security/java.security	Tue Mar 14 08:35:03 2017 -0400
@@ -598,8 +598,8 @@
 #   jdk.certpath.disabledAlgorithms=MD2, DSA, RSA keySize < 2048
 #
 #
-jdk.certpath.disabledAlgorithms=MD2, MD5, RSA keySize < 1024, \
-    DSA keySize < 1024, EC keySize < 224
+jdk.certpath.disabledAlgorithms=MD2, MD5, SHA1 jdkCA & usage TLSServer, \
+    RSA keySize < 1024, DSA keySize < 1024, EC keySize < 224
 
 #
 # Algorithm restrictions for signed JAR files