You are viewing a plain text version of this content. The canonical link for it is here.
Posted to commits@santuario.apache.org by "Colm O hEigeartaigh (Jira)" <ji...@apache.org> on 2021/09/07 06:09:00 UTC
[jira] [Commented] (SANTUARIO-578) Enable configurable Random
number generator in initialization of XMLSecurityConstants
[ https://issues.apache.org/jira/browse/SANTUARIO-578?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17410936#comment-17410936 ]
Colm O hEigeartaigh commented on SANTUARIO-578:
-----------------------------------------------
Yes please submit a PR for it
> Enable configurable Random number generator in initialization of XMLSecurityConstants
> -------------------------------------------------------------------------------------
>
> Key: SANTUARIO-578
> URL: https://issues.apache.org/jira/browse/SANTUARIO-578
> Project: Santuario
> Issue Type: Improvement
> Security Level: Public(Public issues, viewable by everyone)
> Components: Java
> Affects Versions: Java 2.1.2
> Reporter: Sudeep Das
> Assignee: Colm O hEigeartaigh
> Priority: Minor
> Labels: easyfix
>
> Use of hard coded PRNG in XMLSecurityConstants makes it impossible to configure the RNG. SHA1PRNG cannot be used in FIPS 140-2 approved mode
> The change is simple enough via a system property and I can contribute a PR for this if it helps
--
This message was sent by Atlassian Jira
(v8.3.4#803005)