You are viewing a plain text version of this content. The canonical link for it is here.
Posted to commits@santuario.apache.org by "Colm O hEigeartaigh (Jira)" <ji...@apache.org> on 2022/04/20 16:27:00 UTC

[jira] [Updated] (SANTUARIO-578) Enable configurable Random number generator in initialization of XMLSecurityConstants

     [ https://issues.apache.org/jira/browse/SANTUARIO-578?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Colm O hEigeartaigh updated SANTUARIO-578:
------------------------------------------
    Fix Version/s: Java 3.0.0

> Enable configurable Random number generator in initialization of XMLSecurityConstants
> -------------------------------------------------------------------------------------
>
>                 Key: SANTUARIO-578
>                 URL: https://issues.apache.org/jira/browse/SANTUARIO-578
>             Project: Santuario
>          Issue Type: Improvement
>      Security Level: Public(Public issues, viewable by everyone) 
>          Components: Java
>    Affects Versions: Java 2.1.2
>            Reporter: Sudeep Das
>            Assignee: Colm O hEigeartaigh
>            Priority: Minor
>              Labels: easyfix
>             Fix For: Java 3.0.0
>
>
> Use of hard coded PRNG in XMLSecurityConstants makes it impossible to configure the RNG. SHA1PRNG cannot be used in FIPS 140-2 approved mode 
> The change is simple enough via a system property and I can contribute a PR for this if it helps



--
This message was sent by Atlassian Jira
(v8.20.7#820007)