Skip to content

OPENJDK-4013: Update nss.fips.cfg to grant CKA_SIGN and CKA_ENCRYPT to any CKO_SECRET_KEY#39

Closed
franferrax wants to merge 1 commit intorh-openjdk:fips-17ufrom
franferrax:fips-17u
Closed

OPENJDK-4013: Update nss.fips.cfg to grant CKA_SIGN and CKA_ENCRYPT to any CKO_SECRET_KEY#39
franferrax wants to merge 1 commit intorh-openjdk:fips-17ufrom
franferrax:fips-17u

Conversation

@franferrax
Copy link

@fitzsim
Copy link

fitzsim commented Oct 16, 2025

This looks safe to me as long as we can count on NSS to reject operations that are newly allowed by this change, but that are not allowed by FIPS.

Copy link

@fitzsim fitzsim left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This looks safe to me as long as we can count on NSS to reject operations that are newly allowed by this change, but that are not allowed by FIPS.

@gnu-andrew
Copy link

Merged in #44

@gnu-andrew gnu-andrew closed this Feb 3, 2026
@franferrax
Copy link
Author

@gnu-andrew: from now on, I will always make sure to check Allow edits and access to secrets by maintainers. With that option enabled, you should be able to directly push to my fork's branch and update the original PR. This removes the burden of creating a new PR, so feel free to directly push to my branch next time. Understanding you need to rebase, force-pushes won't be considered an offense.

@franferrax franferrax deleted the fips-17u branch February 24, 2026 18:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants