PKCS11-NSS generic keys generated by DH have leading zeroes stripped

XMLWordPrintable

    • Type: Bug
    • Resolution: Fixed
    • Priority: P4
    • 26
    • Affects Version/s: 25, 26
    • Component/s: security-libs
    • None

      JDK-8189441 extended the KeyAgreements to generate "Generic" keys. These keys are intended for use with KDFs, and are supposed to always use the full length.

      When using SunPKCS11 provider with NSS backend, Generic keys generated by DiffieHellman have their leading zeroes stripped.

      To reproduce, extend the existing test named TestLeadingZeroesP11 to cover Generic keys.

            Assignee:
            Daniel Jelinski
            Reporter:
            Daniel Jelinski
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved: