You are viewing a plain text version of this content. The canonical link for it is here.
Posted to commits@santuario.apache.org by "Colm O hEigeartaigh (Jira)" <ji...@apache.org> on 2022/04/20 16:27:00 UTC
[jira] [Updated] (SANTUARIO-578) Enable configurable Random number generator in initialization of XMLSecurityConstants
[ https://issues.apache.org/jira/browse/SANTUARIO-578?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
Colm O hEigeartaigh updated SANTUARIO-578:
------------------------------------------
Fix Version/s: Java 3.0.0
> Enable configurable Random number generator in initialization of XMLSecurityConstants
> -------------------------------------------------------------------------------------
>
> Key: SANTUARIO-578
> URL: https://issues.apache.org/jira/browse/SANTUARIO-578
> Project: Santuario
> Issue Type: Improvement
> Security Level: Public(Public issues, viewable by everyone)
> Components: Java
> Affects Versions: Java 2.1.2
> Reporter: Sudeep Das
> Assignee: Colm O hEigeartaigh
> Priority: Minor
> Labels: easyfix
> Fix For: Java 3.0.0
>
>
> Use of hard coded PRNG in XMLSecurityConstants makes it impossible to configure the RNG. SHA1PRNG cannot be used in FIPS 140-2 approved mode
> The change is simple enough via a system property and I can contribute a PR for this if it helps
--
This message was sent by Atlassian Jira
(v8.20.7#820007)