8369282: Distrust TLS server certificates anchored by Chunghwa ePKI Root CA #255
+244
−2
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Backporting JDK-8369282: Distrust TLS server certificates anchored by Chunghwa ePKI Root CA.
This PR implements OpenJDK distrust of TLS certificates anchored by Chunghwa Telecom's ePKI Root CA (following Google/Mozilla). Certificates issued after March 17, 2026 will be rejected during TLS handshakes in SunJSSE.
For parity with Oracle JDK.
Ran related tests on linux-x64, linux-aarch64, macos-aarch64 and windows-x64:
make test TEST=test/jdk/sun/security/ssl/X509TrustManagerImpl/distrust/Chunghwa.java
Progress
Issues
Reviewing
Using
gitCheckout this PR locally:
$ git fetch https://git.openjdk.org/jdk25u-dev.git pull/255/head:pull/255$ git checkout pull/255Update a local copy of the PR:
$ git checkout pull/255$ git pull https://git.openjdk.org/jdk25u-dev.git pull/255/headUsing Skara CLI tools
Checkout this PR locally:
$ git pr checkout 255View PR using the GUI difftool:
$ git pr show -t 255Using diff file
Download this PR as a diff file:
https://git.openjdk.org/jdk25u-dev/pull/255.diff
Using Webrev
Link to Webrev Comment