alternative JCE providers?
Rhys Smith
Rhys.Smith at jisc.ac.uk
Wed Sep 16 11:47:21 EDT 2015
On 16/09/2015 16:42, "users on behalf of Ian Young" <users-bounces at shibboleth.net on behalf of ian at iay.org.uk> wrote:
>
>> On 16 Sep 2015, at 15:22, Cantor, Scott <cantor.2 at osu.edu> wrote:
>>
>> If you want AES-256, yes. I don't know what else requires it. I also didn't know how OpenJDK handled that. I assumed they must be including the stronger files, or supplying them via the OS' packaging system.
>
>I'm pretty sure that OpenJDK includes the stronger crypto by default, it's just the Oracle package that doesn't.
It does, no need for custom JCE stuff on OpenJDK.
Just to confirm my memory was correct, just checked what the max allowed AES keylength is on openjdk 1.8 installed via RPM on CentOS 7 - by looking at output of javax.crypto.Cipher.getMaxAllowedKeyLength("AES”) - and it’s 2147483647. So it’ll have a problem come AES-2147483648. AES-256 should be fine.
Rhys.
Jisc is a registered charity (number 1149740) and a company limited by guarantee which is registered in England under Company No. 5747339, VAT No. GB 197 0632 86. Jisc’s registered office is: One Castlepark, Tower Hill, Bristol, BS2 0JA. T 0203 697 5800.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 5069 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/users/attachments/20150916/562ce417/attachment-0001.p7s>
More information about the users
mailing list