You are viewing a plain text version of this content. The canonical link for it is here.
Posted to commits@santuario.apache.org by "Colm O hEigeartaigh (Jira)" <ji...@apache.org> on 2021/09/07 06:09:00 UTC

[jira] [Commented] (SANTUARIO-578) Enable configurable Random number generator in initialization of XMLSecurityConstants

    [ https://issues.apache.org/jira/browse/SANTUARIO-578?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17410936#comment-17410936 ] 

Colm O hEigeartaigh commented on SANTUARIO-578:
-----------------------------------------------

Yes please submit a PR for it

> Enable configurable Random number generator in initialization of XMLSecurityConstants
> -------------------------------------------------------------------------------------
>
>                 Key: SANTUARIO-578
>                 URL: https://issues.apache.org/jira/browse/SANTUARIO-578
>             Project: Santuario
>          Issue Type: Improvement
>      Security Level: Public(Public issues, viewable by everyone) 
>          Components: Java
>    Affects Versions: Java 2.1.2
>            Reporter: Sudeep Das
>            Assignee: Colm O hEigeartaigh
>            Priority: Minor
>              Labels: easyfix
>
> Use of hard coded PRNG in XMLSecurityConstants makes it impossible to configure the RNG. SHA1PRNG cannot be used in FIPS 140-2 approved mode 
> The change is simple enough via a system property and I can contribute a PR for this if it helps



--
This message was sent by Atlassian Jira
(v8.3.4#803005)