<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" "http://www.w3.org/TR/REC-html40/loose.dtd">
<html lang="en" style='--code-editor-font: var(--default-mono-font, "GitLab Mono"), JetBrains Mono, Menlo, DejaVu Sans Mono, Liberation Mono, Consolas, Ubuntu Mono, Courier New, andale mono, lucida console, monospace;'>
<head>
<meta content="text/html; charset=utf-8" http-equiv="Content-Type">
<title>
GitLab
</title>
<style data-premailer="ignore" type="text/css">
a { color: #1068bf; }
</style>
<style>img {
max-width: 100%; height: auto;
}
body {
font-size: .875rem;
}
body {
-webkit-text-shadow: hsla(0,0%,100%,.01) 0 0 1px;
}
body {
font-family: "GitLab Sans",-apple-system,BlinkMacSystemFont,"Segoe UI",Roboto,"Noto Sans",Ubuntu,Cantarell,"Helvetica Neue",sans-serif,"Apple Color Emoji","Segoe UI Emoji","Segoe UI Symbol","Noto Color Emoji"; font-size: inherit;
}
</style>
</head>
<body style='font-size: inherit; -webkit-text-shadow: hsla(0,0%,100%,.01) 0 0 1px; font-family: "GitLab Sans",-apple-system,BlinkMacSystemFont,"Segoe UI",Roboto,"Noto Sans",Ubuntu,Cantarell,"Helvetica Neue",sans-serif,"Apple Color Emoji","Segoe UI Emoji","Segoe UI Symbol","Noto Color Emoji";'>
<div class="content">
<h3 style="margin-top: 20px; margin-bottom: 10px;">
Timo Aaltonen pushed to branch upstream at <a href="https://salsa.debian.org/freeipa-team/jss">FreeIPA packaging / jss</a>
</h3>
<h4 style="margin-top: 10px; margin-bottom: 10px;">
Commits:
</h4>
<ul>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/ca596e99bd9e3ce60639f82fa3ae30bcc0216f6c">ca596e99</a></strong>
<div>
<span> by Marco Fargetta </span> <i> at 2026-01-15T16:27:22+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Update version number to 5.10.0-alpha1
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/7228b4998b82e6cebaf2f23b3dca8874cf553ddc">7228b499</a></strong>
<div>
<span> by Marco Fargetta </span> <i> at 2026-01-15T16:50:04+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>update pom.xml version
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/9af1e2b99feb4a9fef64d7d339ee5efe3f9139a6">9af1e2b9</a></strong>
<div>
<span> by Marco Fargetta </span> <i> at 2026-01-16T12:01:05+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Fix spec file error blocking the build
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/6c33e42f72b82e67b0adf3e45a088504fae2fe28">6c33e42f</a></strong>
<div>
<span> by Endi S. Dewata </span> <i> at 2026-01-22T15:34:41-06:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Clean up RPM spec
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/8e0658f0e6bd0ca452502512839ef97035a27838">8e0658f0</a></strong>
<div>
<span> by Endi S. Dewata </span> <i> at 2026-01-22T15:34:45-06:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Fix CI for Fedora 42
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/e4d073eb897fff11c7b824366f5310e3b8ba8ff2">e4d073eb</a></strong>
<div>
<span> by Endi S. Dewata </span> <i> at 2026-01-22T16:33:36-06:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Fix typos
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/1c27f8a8ee7ff7d4e5d476e41335b268ed6ce139">1c27f8a8</a></strong>
<div>
<span> by Endi S. Dewata </span> <i> at 2026-01-27T00:01:50+07:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Fix Tomcat tests
The Tomcat tests have been updated to work with the latest
Tomcat and OpenSSL on Fedora 42 and 43.
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/6aba7c4ce132c6c2cf6b75151d2df819612743f3">6aba7c4c</a></strong>
<div>
<span> by Endi S. Dewata </span> <i> at 2026-01-26T11:26:52-06:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Fix Azure pipeline
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/f3d05b27213e30091b81ba58d861e77d01a6b65d">f3d05b27</a></strong>
<div>
<span> by Jack Magne </span> <i> at 2026-01-26T17:30:05-08:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Fix inconsistent template for lunasa when generating tempoary private key as part of recovering private key for the kra.
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/84277e4c6bee127b35e90deb996d49c55240cf03">84277e4c</a></strong>
<div>
<span> by Marco Fargetta </span> <i> at 2026-02-04T09:34:16+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Customisable SSL buffer size
Buffer size for RSA and EC could be too small for PQC algorithms with
problem to read SSL packets.
The buffer size has been made customisable using the java option
`jdk.tls.maxHandshakeMessageSize` but the default value has not been
modified.
Additionally, in case the buffer become full and the communication
is not working because the packet cannot stay in the buffer, an SSL
exception is raised with a proper message so the admin can modify
the configuration.
Assisted-by: Claude
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/4ce26f7215f092945b2020f310a31d9032dcdc7e">4ce26f72</a></strong>
<div>
<span> by Endi S. Dewata </span> <i> at 2026-02-09T14:40:06-06:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Add test-init.sh
The test-init.sh has been added to initialize the default
values of some environment variables in several branches.
This way the same code can be used in multiple branches
which simplifies the branching process.
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/a62ef7543229addc7aed08b31b755400e74aef0a">a62ef754</a></strong>
<div>
<span> by Endi S. Dewata </span> <i> at 2026-02-10T17:33:57-06:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Fix default values in test-init.sh
The test-init.sh has been updated to set the default values
of environment variables properly for all branches.
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/da0bd3d03528ab586f32a88d4ddd659fffc5398e">da0bd3d0</a></strong>
<div>
<span> by Endi S. Dewata </span> <i> at 2026-02-10T19:20:32-06:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Fix default values for v5.9 branch
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/5c441656c4b91719dcf9814cf09d5427b2d6310b">5c441656</a></strong>
<div>
<span> by Marco Fargetta </span> <i> at 2026-02-19T17:28:26+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Fix application data send with multiple packets
The additional check for buffer size to avoid looping in case of big
handshake packets was blocking also the application data to be sent.
To avoid limiting the application data an additional check on the
handshake status is included. If the handshake is complete then the
buffer size can contain the handshake packets and there is no need to
perform additional checks.
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/d903f927943a4fceea89204388a72b92087a257c">d903f927</a></strong>
<div>
<span> by Vladimir Petko </span> <i> at 2026-03-17T10:00:00+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>fix: use size_t in call to JSS_FromByteArray
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/ebf29b7934a308484b263b3dc33267d23fc3edde">ebf29b79</a></strong>
<div>
<span> by Vladimir Petko </span> <i> at 2026-03-17T10:00:00+01:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>fix: add overflow check.
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/c527e376a5fd6e6812f6ad262f2ed83cec314f30">c527e376</a></strong>
<div>
<span> by Endi S. Dewata </span> <i> at 2026-03-19T12:04:44-05:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Use Java 21 on Fedora 43
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/7eb0818c78d7c3a7e3fa97d3cf906477a48ef45b">7eb0818c</a></strong>
<div>
<span> by Endi S. Dewata </span> <i> at 2026-03-23T08:49:52-07:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Fix race condition segfault in JSSEngineReferenceImpl cleanup
The finalizer thread was experiencing segfaults during PR.Shutdown()
calls due to a race condition where multiple threads could execute
cleanup operations simultaneously on the same object.
Root cause:
- cleanup(), closeInbound(), closeOutbound(), and tryCleanup()
methods were not synchronized
- Multiple threads could simultaneously check and modify the boolean
flags (closed_fd, is_inbound_closed, is_outbound_closed)
- One thread could close/free ssl_fd while another thread was still
using it in PR.Shutdown(), causing SIGSEGV in NSS memcpy
Changes:
- Add synchronized modifier to closeInbound(), closeOutbound(),
cleanup(), and tryCleanup() methods
- The synchronized keyword provides both mutual exclusion (only one
thread can execute these methods at a time) and memory visibility
(changes to fields are visible to other threads)
This prevents concurrent cleanup operations from corrupting the native
PRFileDesc pointer and eliminates the segfault during finalization.
Assisted-by: Claude Sonnet 4.5
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/cc8899742ce94797572f3ac888b1cb73838e5b20">cc889974</a></strong>
<div>
<span> by Endi S. Dewata </span> <i> at 2026-04-03T10:17:13-05:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Update Password.readPasswordFromConsole()
The Password.readPasswordFromConsole() has been modified to
read the password from the standard input in case the system
console is not available (e.g. in CI environment).
Assisted-by: Gemini Code Assist
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/bd994f97be64b1ad0aaf9e2bc51b74e86c490ea8">bd994f97</a></strong>
<div>
<span> by Endi S. Dewata </span> <i> at 2026-04-06T19:09:26+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Clean up exception messages in PKCS7.parse()
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/3a9ef779009731bd76c89f7d2b09613f93f6c6ec">3a9ef779</a></strong>
<div>
<span> by Endi S. Dewata </span> <i> at 2026-04-21T19:40:37-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Fix TOCTOU race condition in JSSEngineReferenceImpl cleanup
The finalizer thread was still experiencing segfaults after the initial
synchronization fix (7eb0818c) due to a time-of-check to time-of-use
race condition in cleanupSSLFD().
Root cause:
- The closed_fd flag was set in the finally block AFTER native resources
were freed (ssl_fd.close())
- Another thread could call closeInbound()/closeOutbound(), check
!closed_fd (still false), and attempt PR.Shutdown() on the already-freed
ssl_fd pointer, causing SIGSEGV in NSS memcpy
The fix:
- Set closed_fd = true BEFORE freeing native resources
- This ensures the guard checks in closeInbound()/closeOutbound() will
prevent any concurrent PR.Shutdown() calls on ssl_fd that is being freed
- Remove finally block since closed_fd is now set before exception can occur
This completes the fix for the race condition segfault in cleanup.
Assisted-by: Claude Sonnet 4.5
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/5e4a2cc2b7679a269e2f212b8d7e51c8bcb2f8a7">5e4a2cc2</a></strong>
<div>
<span> by Endi S. Dewata </span> <i> at 2026-04-24T15:46:42-04:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Update Tomcat cipher test
Due to recent changes in Tomcat the cipher test needs to be
updated to configure the TLS 1.2 ciphers and TLS 1.3 cipher
suites in separate attributes in server.xml.
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/a537df46999aec9ef1394f487948a5313ccfdc13">a537df46</a></strong>
<div>
<span> by Endi S. Dewata </span> <i> at 2026-04-27T09:07:37-05:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Update CryptoManager.findCertByNickname() to require nickname
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/fccefb9e889e6d065342c77099d1b20523700307">fccefb9e</a></strong>
<div>
<span> by Endi S. Dewata </span> <i> at 2026-04-29T13:43:39-05:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Update RPM spec to use %autochangelog
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/f1afa0efa72de0359fd8e5236f5705bde4dfc591">f1afa0ef</a></strong>
<div>
<span> by Marco Fargetta </span> <i> at 2026-05-07T11:28:18+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Enable ML-DSA key pair initialisation with named parameter
JSR spec 497 [1] define key pair generation using named paramter for
ML-DSA but current implementation was using only key strength to
follow NSS implementation. Therefore, the initialisation with named
parameter is enabled. Note, named parameter for ML-DSA are defined
only for java >= 24, if used with previous version the parameter has
to be defined.
Additionally, fix jss.map version for MLDSA related method.
1. https://openjdk.org/jeps/497
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/f1bbb636cce984804bc1e836462ac75ce58145b6">f1bbb636</a></strong>
<div>
<span> by Marco Fargetta </span> <i> at 2026-05-07T11:28:18+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Add ML-KEM key pair generation
Key pair generation now support ML-KEM key type. The support follows
the JEP#496 [1]. The key generation instance has to be requested for
the algorithm "ML-KEM" or one of its variants ("ML-KEM-512",
"ML-KEM-768" or "ML-KEM-1024"). If the generic algorithm is used and
it is not followed by initialisation then the key will be
"ML-KEM-768".
Initialisation can be done with a NamedParameterSpec indicating the
variant ("ML-KEM-512", "ML-KEM-768" or "ML-KEM-1024") or with the
related strength (512, 768 or 1024).
1. https://openjdk.org/jeps/496
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/ab95759493f475becf151b497c1ecf1002492cef">ab957594</a></strong>
<div>
<span> by Marco Fargetta </span> <i> at 2026-05-07T11:28:18+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Add ML-KEM KeyType support with JNI bindings
Add MLKEM KeyType to KeyType.java and corresponding JNI mappings in
PK11PrivKey/PK11PubKey for kyberKey handling. Includes test coverage
for ML-KEM-768 and ML-KEM-1024 key pair generation.
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/52534e7e6b27bf336f56d57b238789ea533886ca">52534e7e</a></strong>
<div>
<span> by jmagne </span> <i> at 2026-05-11T17:53:16-07:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Add PBMAC1 ASN.1 structures and configuration API.
Assisted-by: Claude Sonnet 4.5
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/48a3fe8ee2b514eef503a62ff1e66065f34d110a">48a3fe8e</a></strong>
<div>
<span> by jmagne </span> <i> at 2026-05-11T17:53:16-07:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Implement PBMAC1 MAC computation for PKCS#12:
Assisted by: Claude Sonnet 4.5
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/c8c42bca1fc0ee01c3161a4487f5761bf6e2cb05">c8c42bca</a></strong>
<div>
<span> by jmagne </span> <i> at 2026-05-11T17:53:16-07:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Add PBMAC1 test suite and CI integration:
Assisted-by: Claude Sonnet 4.5
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/49f2ceb5d7ec5bc4f2b0663eed78fbcba2d369b0">49f2ceb5</a></strong>
<div>
<span> by Marco Fargetta </span> <i> at 2026-05-12T19:57:16+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Add ML-KEM encapsulation and decapsulation support
Implements KEMSpi with JNI bindings to NSS PK11_Encapsulate and
PK11_Decapsulate. Adds support for ML-KEM-512, ML-KEM-768, and
ML-KEM-1024 variants with HKDF key derivation for AES algorithms.
Bumps Java version requirement to 21 for KEM API support.
Assisted-By: Claude Sonnet 4.5 <noreply@anthropic.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/1ab79fe547aad0769ddb9ad7c02e5ede97fce843">1ab79fe5</a></strong>
<div>
<span> by Marco Fargetta </span> <i> at 2026-05-12T19:57:16+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Add check for matching key with KEM algorithm
JEP #496 [1] requires that key algorithm have to match KEM algorithm
if a specific strngth is requested. The check is implemented in
JSSKEMSpi when a new encapsulator or decapsualtor is generated.
1. https://openjdk.org/jeps/496
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/45862bd3114a944b65c6381891f117329447dcea">45862bd3</a></strong>
<div>
<span> by Marco Fargetta </span> <i> at 2026-05-12T19:57:16+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Add ML-KEM encapsulation and decapsulation tests
Implements comprehensive test coverage for ML-KEM key encapsulation
mechanism, validating encapsulate/decapsulate operations across
multiple parameter sets (ML-KEM-768, ML-KEM-1024) and AES key sizes.
ML-KEM Key strength has to match with KEM algorithm. The test also
verify this control is enforced.
Assisted-By: Claude Sonnet 4.5 <noreply@anthropic.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/2cec7180e34d12c6339b78d473a0d6fbfbaa1357">2cec7180</a></strong>
<div>
<span> by Marco Fargetta </span> <i> at 2026-05-12T19:57:16+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Update PKCS11 constatnt to NSS 3.123
Fix: #1092
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/f7d68cbf93d8268b112e4187c89630299715ce03">f7d68cbf</a></strong>
<div>
<span> by Endi S. Dewata </span> <i> at 2026-05-12T18:18:42-05:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Define OIDs for ML-KEM
The AlgorithmId has been updated to define the OIDs for ML-KEM
algorithms. They are needed for certificate enrollments with
ML-KEM keys.
https://csrc.nist.gov/projects/computer-security-objects-register/algorithm-registration
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/fce63513b2e7cf93027802936bfc2d9fdd02d78a">fce63513</a></strong>
<div>
<span> by Marco Fargetta </span> <i> at 2026-05-14T17:19:46+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Update java build to java jdk 25
KEM algorithms are supported from Java 23 so the jdk has to be updated in order to build the code.
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/2502b23b496cd62e4e9940848e13f2d0da4b11ca">2502b23b</a></strong>
<div>
<span> by Christina Fu </span> <i> at 2026-05-14T08:57:44-07:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Add ML-KEM and ML-DSA key archival and recovery support (#1098)
This commit adds support for ML-KEM (Module-Lattice-Based Key
Encapsulation Mechanism) and ML-DSA (Module-Lattice-Based Digital
Signature Algorithm) key archival and recovery in JSS.
- JSSProvider.java: Add KeyFactory.ML-KEM and KeyFactory.ML-DSA
generic aliases for KeyFactory support
- PrivateKey.java:
* Add top-level constants for both ML-KEM and ML-DSA
(MLKEM512, MLKEM768, MLKEM, MLKEM1024, MLDSA44, MLDSA65, MLDSA, MLDSA87)
* Add javadoc documenting generic aliases (MLKEM→MLKEM768, MLDSA→MLDSA65)
- PK11KeyWrapper.java:
* Add unified ML-KEM and ML-DSA public key extraction using SubjectPublicKeyInfo
(de-duplicated into single branch for easier maintenance)
* Add BIT_STRING padding verification to ensure byte-alignment per FIPS 203/204
* Update algFromType() to return MLKEMFamily and MLDSAFamily
* Fix leading-zero stripping to only apply to RSA/DSA (preserves EC/PQC bytes)
* Catch specific InvalidBERException instead of generic Exception
- PK11KeyWrapper.c:
* Add workarounds for NSS PK11_GetKeyType() not mapping ML-KEM and ML-DSA mechanisms
* Add CKK_ML_KEM case with CKA_DECAPSULATE attribute per PKCS#11 v3.2
(KEMs use CKA_DECAPSULATE, similar to DH/ECDH using CKA_DERIVE)
* Add CKK_ML_DSA case with CKA_SIGN attribute per PKCS#11 v3.2
(ML-DSA is a signature algorithm)
ML-KEM support has been tested and verified to work with hsmCompatVerify tool.
ML-DSA support is added for forward-thinking purposes. It is untested but
follows the same pattern as ML-KEM.
IDM-5475 IDM-5817 IDM-6295
Assisted-by: Claude</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/990d7291afb377eb22f162968e7836363498c5e5">990d7291</a></strong>
<div>
<span> by Marco Fargetta </span> <i> at 2026-05-18T11:51:20+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Add ML-DSA and ML-KEM algorithm parameter support
- Update PrivateKey interface documentation to include ML-DSA and ML-KEM
- Fix exception handling in PK11PrivKey.getType() to throw KeyException
instead of PK11Exception for unsupported parameter sets
- Implement getParams() to return NamedParameterSpec for ML-DSA and ML-KEM keys
- Update getAlgorithm() to use getKeyType() to avoid exception in call path
- Handle KeyException in JSSKEMSpi key validation
These changes complete the ML-KEM integration by properly exposing
algorithm parameters and aligning exception types with the interface
contract.
Assisted-By: Claude Sonnet 4.5 <noreply@anthropic.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/9bc42c3106086266a155271ffe6c155ac7b4e179">9bc42c31</a></strong>
<div>
<span> by Marco Fargetta </span> <i> at 2026-05-18T11:51:20+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Fix CMake build error
If the build is done with CMake, without PQC enabled there is an error
the file `PK11PrivKey.c` does not compile because the variable
`paramSet` result undefined. The definition is moved outside the macro
to be always available.
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/6b5b699eb37cc05ee4b902956e14671e289ab620">6b5b699e</a></strong>
<div>
<span> by Marco Fargetta </span> <i> at 2026-05-18T11:51:20+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Revert Java minimum version to 21
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/143d98c95a412db7717aec14a8b0cf56a69a8d91">143d98c9</a></strong>
<div>
<span> by Christina Fu </span> <i> at 2026-05-18T09:08:31-07:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Add JSS unit tests for ML-KEM key wrapping with AES-KWP (#1100)
* Fix PQC key wrapping support in JSS native code
- Update MAX_WRAPPED_KEY_LEN comment to document PQC key size requirements.
Existing 4096 bytes is sufficient for ML-KEM-1024 (~3280 bytes wrapped).
- Fix PK11PrivKey.c compilation: Move paramSet variable declaration outside
ifdef to prevent "undeclared identifier" error on line 276 return statement.
These fixes enable wrapping/unwrapping of post-quantum cryptographic keys
including ML-KEM-1024 and ML-DSA-44.
Note: ML-DSA-44 is currently the largest ML-DSA variant that NSS can wrap.
Larger variants (ML-DSA-65, ML-DSA-87) fail in NSS with SEC_ERROR_OUTPUT_LEN
even with larger buffers - this is an NSS limitation, not a buffer size issue.
IDM-5475 IDM-5817
Assisted-by: Claude
* Add JSS unit tests for ML-KEM key wrapping with AES-KWP
This commit adds comprehensive unit tests for post-quantum key wrapping
functionality using ML-KEM (FIPS 203) for key encapsulation and AES-KWP
(RFC 5649) for key wrapping.
Test coverage:
- ML-KEM-768 encapsulation to derive AES-256 wrapping key
- Wrapping/unwrapping RSA-2048, EC P-256, ML-KEM-1024, and ML-DSA-44
private keys using AES-KWP (CKM_AES_KEY_WRAP_KWP)
- Cryptographic verification of unwrapped keys via sign/verify operations
- Decapsulation verification proving recovered key matches wrapping key
Implementation:
- Test suite with 4 test cases in MLKEMKeyWrapping.java
- Registered for both regular and FIPS mode testing
- Uses java.security configuration for database location
- StandardCharsets.UTF_8 for consistent string encoding
- sensitivePairs(true) for FIPS mode compatibility
- Updated Disable_FipsMODE dependencies to include PQC FIPS tests
Requirements:
- NSS 3.123+ with PQC support
- Build with -DENABLE_NSS_VERSION_PQC_DEF=ON to enable tests
- Tests are optional and won't break builds on older NSS versions
Note: ML-DSA-44 is currently the largest ML-DSA variant that NSS can
successfully wrap. Larger variants (ML-DSA-65, ML-DSA-87) fail with
SEC_ERROR_OUTPUT_LEN.
IDM-6295
Assisted-by: Claude</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/51b2e0c6964d92f8ee245bfa5e5aa6a0f5aad6d4">51b2e0c6</a></strong>
<div>
<span> by Endi S. Dewata </span> <i> at 2026-05-18T23:22:05+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Fix build warnings in sslget.c
- Replace pointer-to-int cast warnings with proper %p format specifiers
- Remove unused SECStatus result variable
- Remove unused getIPAddress function
Co-Authored-By: Claude Sonnet 4 <noreply@anthropic.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/c83dd712863397f4824e061ddc74ed42ef15c433">c83dd712</a></strong>
<div>
<span> by Endi S. Dewata </span> <i> at 2026-05-18T23:58:19+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Fix build warnings in SessionKey.cpp
- Fix infinite recursion in JSS_PK11_wrapSymKey by adding forward declaration
and calling the 3-parameter overload instead of calling itself
- Fix strncpy truncation warnings by using KEYNAMELENGTH-1 and explicit
null termination to ensure proper string handling
Co-Authored-By: Claude Sonnet 4 <noreply@anthropic.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/c260855bd4f423ad9c01f932360f3dd5d85d57d5">c260855b</a></strong>
<div>
<span> by Endi S. Dewata </span> <i> at 2026-05-19T00:21:02+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Fix build warnings in SymKey.cpp
- Remove unused count variables in DeleteKey and ListSymmetricKeys functions
- Remove unnecessary NULL check for local array fullNewMasterKeyName
- Fix strncpy truncation warning by using KEYNAMELENGTH-1 and explicit
null termination to ensure proper string handling
Co-Authored-By: Claude Sonnet 4 <noreply@anthropic.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/c5d810a1bde4651eae59699062767c319a40941e">c5d810a1</a></strong>
<div>
<span> by Endi S. Dewata </span> <i> at 2026-05-19T00:23:26+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Fix build warning in p7tool secpwd.c
- Add proper error handling for fgets return value in SEC_GetPassword
- Check for NULL return from QUIET_FGETS and return early on EOF/error
- Add length check before removing newline to prevent buffer underrun
- This resolves the [-Wunused-result] warning for fgets
Co-Authored-By: Claude Sonnet 4 <noreply@anthropic.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/c0d1dae61bd110b9fe2a821a884ade64ad015743">c0d1dae6</a></strong>
<div>
<span> by Endi S. Dewata </span> <i> at 2026-05-19T01:15:01+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Fix build warnings in p7tool secutil.c
- Add proper error handling for PK11_InitPin return value in SECU_ChangePW
- Replace deprecated CERTDB_VALID_PEER with CERTDB_TERMINAL_RECORD
- Fix pointer-to-int cast warnings by using uintptr_t intermediate cast
- Add stdint.h include for uintptr_t type
- This resolves unused variable, deprecation, and cast warnings
Co-Authored-By: Claude Sonnet 4 <noreply@anthropic.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/f3dab7459b55edb6e41b1caeaeeef13ce498a530">f3dab745</a></strong>
<div>
<span> by Endi S. Dewata </span> <i> at 2026-05-19T01:15:01+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Fix build warnings in p7tool.c
- Add error checking for fwrite() return value to resolve unused variable warning
in DecodeAndPrintFile function - now properly reports write failures
- Change prefix parameter and variable to const char* to resolve const qualifier
warning when assigning from optstate->value
- This improves error handling and type safety
Co-Authored-By: Claude Sonnet 4 <noreply@anthropic.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/0bac6a1263720a830e77ac421059ff605c1cc8fd">0bac6a12</a></strong>
<div>
<span> by Endi S. Dewata </span> <i> at 2026-05-19T01:15:01+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Fix Javadoc errors in multiple Java files
- CryptoManager.java: Fix missing parameter name in @param tag
- DirStrConverter.java: Remove invalid @param, @return, @throws tags from field documentation
- JSSContext.java: Fix missing class references and correct method signatures
- JSSNioEndpoint.java: Fix malformed {@link} tag with text outside braces
- JSSSecureNioChannel.java: Fix malformed {@link} tag with text outside braces
- MacData.java: Correct @param tags to match actual method parameters
- PKCS9Attribute.java: Fix incorrect parameter name in @param tag
- PKCS9Attributes.java: Fix incorrect parameter name in @param tag
These fixes resolve Javadoc generation warnings and improve documentation accuracy.
Co-Authored-By: Claude Sonnet 4 <noreply@anthropic.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/b0b79c933916c4e2fb638d8efa233252a2f9f86e">b0b79c93</a></strong>
<div>
<span> by Endi S. Dewata </span> <i> at 2026-05-19T18:29:13+00:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Add Maven build option to jss.spec
Add %bcond_without maven option to allow optional CMake-only builds. By
default, Maven builds Java code and CMake builds native code. When
--without maven is specified, CMake builds everything including Java code.
Co-Authored-By: Claude Sonnet 4 <noreply@anthropic.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/36995fb53755daeb7d14c2936a969a6152b44a53">36995fb5</a></strong>
<div>
<span> by Marco Fargetta </span> <i> at 2026-05-21T09:55:18+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Fix default ML-DSA signing
According to JEP 497 [1], the ML-DSA signature algorithm should behave
as follows:
- When instantiated as "ML-DSA" (generic), it accepts any ML-DSA-44,
ML-DSA-65, or ML-DSA-87 key and uses the key's variant
- When instantiated with a specific variant (e.g., "ML-DSA-65"), it
only accepts keys of that variant, throwing InvalidKeyException
otherwise
Previously, the generic "ML-DSA" was hardcoded to "ML-DSA-65", which
worked in practice because NSS uses the key's variant regardless of
the signature algorithm parameter. However, this violated the JEP
497 specification.
This commit implements the correct behavior:
- Generic ML-DSA signature extracts the variant from the key
(NamedParameterSpec for private keys, OID from X.509 encoding for
public keys)
- Specific ML-DSA variants validate that the key matches
1. https://openjdk.org/jeps/497
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/5e7980a75c6bd409d2a8ae7ac4f00b2c9e7e49be">5e7980a7</a></strong>
<div>
<span> by Marco Fargetta </span> <i> at 2026-05-25T10:23:25+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Force SHA-512 digest algorithm for ML-DSA in CMS SignerInfo
Per RFC 9882 Section 4 [1], ML-DSA signatures in CMS must use SHA-512
as the digest algorithm identifier in the SignerInfo structure. This
applies both when signed attributes are absent (pure signatures) and
when they are present.
ML-DSA (FIPS 204) is a pure signature algorithm that does not have an
associated digest algorithm like traditional composite signature
algorithms (e.g., RSASignatureWithSHA256). However, RFC 9882 mandates
that the digestAlgorithm field in SignerInfo MUST be set to id-sha512
to ensure proper CMS structure and interoperability.
This change explicitly sets the digest algorithm to SHA-512 when
ML-DSA signature algorithms is ML-DSA-44, ML-DSA-65 or ML-DSA-87).
1. RFC 9882 - Using ML-DSA in the Cryptographic Message Syntax (CMS)
(https://www.rfc-editor.org/rfc/rfc9882)
Assisted-By: Claude Sonnet 4.5 <noreply@anthropic.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/77142a0eaa8e63b550baaa2c987300e097165f58">77142a0e</a></strong>
<div>
<span> by Endi S. Dewata </span> <i> at 2026-05-29T14:40:45-05:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Clean up exception messages in PK11KeyPairGenerator
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/c0712b039c71b3c1c57768972d1d29233eed4e32">c0712b03</a></strong>
<div>
<span> by Endi S. Dewata </span> <i> at 2026-06-01T19:48:02-05:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Add build options for ML-DSA and ML-KEM
The build scripts have been updated to provide options to build
without ML-DSA or ML-KEM since some platforms might only have a
partial or no support of PQC. Note that if ML-DSA is disabled
ML-KEM will be disabled as well, but ML-KEM can be disabled
without affecting ML-DSA.
The following params have been replaced with more specific
params:
- ENABLE_NSS_VERSION_PQC_DEF
- NSS_VERSION_PQC_DEF
- test.NSS_PQC
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/a653cf48819fdad522ac62e58989e0924bcc9765">a653cf48</a></strong>
<div>
<span> by Endi S. Dewata </span> <i> at 2026-06-02T10:42:06-05:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Temporarily enable ML-KEM on RHEL using NSS COPR build
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/1bd6762cf8d4af425c0b1f8695fddbfc93c649ae">1bd6762c</a></strong>
<div>
<span> by Endi S. Dewata </span> <i> at 2026-06-03T10:26:31-05:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Update version number to 5.10.0-beta2
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/a74e29ac70999ff006db1f5d8bd79d34d63f8525">a74e29ac</a></strong>
<div>
<span> by Endi S. Dewata </span> <i> at 2026-06-04T15:21:18-05:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Update build scripts to use Java 21
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/2c7c207ab22c5b90b8fd64a4d4f75e0b08fd84ce">2c7c207a</a></strong>
<div>
<span> by Endi S. Dewata </span> <i> at 2026-06-04T15:21:18-05:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Clean up test messages
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/c60862c9863be9fa54e99a72b1e894515c7aa2d4">c60862c9</a></strong>
<div>
<span> by Endi S. Dewata </span> <i> at 2026-06-04T15:21:18-05:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Clean up build messages
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/10c7772bdae9572d1b03ce4e94a7ef7c1bcfda3d">10c7772b</a></strong>
<div>
<span> by Endi S. Dewata </span> <i> at 2026-06-05T15:11:06-05:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Cleean up Maven scripts
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/d6a6c68710c2fae5d16364422180c1cb4f2cd80e">d6a6c687</a></strong>
<div>
<span> by Endi S. Dewata </span> <i> at 2026-06-08T10:15:30-05:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Update publish job to use Java 21
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/0a98876327ac398ad2b428ff044c8e75bc215706">0a988763</a></strong>
<div>
<span> by Marco Fargetta </span> <i> at 2026-06-11T10:01:37+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Increase TLS buffer size for ML-DSA certificates
ML-DSA certificates require ~50KB for handshake (vs 18KB default). Add
automatic detection of PQC keys and increase buffer to 64KB when
needed. Respects jdk.tls.maxHandshakeMessageSize system property.
Assisted-By: Claude Sonnet 4.5 <noreply@anthropic.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/95c1c839ae88096ff99fae5ac5b1d0383133fdad">95c1c839</a></strong>
<div>
<span> by Marco Fargetta </span> <i> at 2026-06-12T13:18:19+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Fix use-after-free crash in JSSEngineReferenceImpl finalizer
Set `closed_fd` before calling `closeInbound()/closeOutbound()` in
cleanup() to prevent them from calling `PR.Shutdown()` on `ssl_fd`
that is being freed. This fixes a SIGSEGV crash where `PR.Shutdown()`
attempted to write TLS close_notify alerts to NSS buffers during
cleanup.
The crash occurred because `cleanup()` called `closeOutbound()` which
checked `!closed_fd` and invoked `PR.Shutdown()`, but `cleanupSSLFD()` set
`closed_fd` too late. Moving `closed_fd = true` to the start of `cleanup()`
prevents the native `PR.Shutdown()` call while still freeing all
resources properly.
Assisted-by: Claude Sonnet 4.5 <noreply@anthropic.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/ce561a0b43036d8645f8d45a17dfe0a24de47c32">ce561a0b</a></strong>
<div>
<span> by Marco Fargetta </span> <i> at 2026-06-12T13:18:19+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Show pki core dumps in case of segmentation fault
PKI CLI could crash during TLS operations if not properly managed.
The stack dump of the crash is stored in a file from the JVM and it is
shown.
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/85998301ccdadb2e557cd53bb40b8cd8d59aad8e">85998301</a></strong>
<div>
<span> by Endi S. Dewata </span> <i> at 2026-06-16T11:16:15-05:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Update tests to use actions/cache@v5
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/eb86b549b09b16b9655ecc6ec88b74f570a3f9f3">eb86b549</a></strong>
<div>
<span> by jmagne </span> <i> at 2026-06-16T12:55:56-07:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>First cut of using Cleaner object to eliminate the SSLEngine finalizer problem.
Some cleanup suggested by review bots.
Assisted-by: claude Sonnet 4.5.
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/80d1aa54db26d3f4fe7beda4b1ff94ac1e744b23">80d1aa54</a></strong>
<div>
<span> by Endi S. Dewata </span> <i> at 2026-06-16T15:45:09-05:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Fix warnings due to deprecated --pkcs12-password option
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/3de433a3a32080fb2855665474a7cc78a0a710a0">3de433a3</a></strong>
<div>
<span> by Endi S. Dewata </span> <i> at 2026-06-16T15:45:09-05:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Update version number to 5.10.0
The obsolete TestPKCS11Constants has been removed.
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/a06e29f5c0d9dbdba0fb5c34f44c73e117939959">a06e29f5</a></strong>
<div>
<span> by freddy </span> <i> at 2026-06-18T12:06:57+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Allow for encrypting with CKM_AES_KEY_WRAP_KWP
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/5678fbc260e5a979b55832a4bc16036eee892d68">5678fbc2</a></strong>
<div>
<span> by Freddy113-x </span> <i> at 2026-06-18T12:06:57+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Update base/src/main/java/org/mozilla/jss/crypto/EncryptionAlgorithm.java
Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com></pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/0aade72dd2232ee7d6161be347568f5575e8fcf1">0aade72d</a></strong>
<div>
<span> by Endi S. Dewata </span> <i> at 2026-06-18T12:47:19-05:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Update tests to use actions/checkout@v7
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/e0b60ceb25fc0d2b94d7ac72de10e51000765c7c">e0b60ceb</a></strong>
<div>
<span> by Endi S. Dewata </span> <i> at 2026-06-18T12:47:19-05:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Update tests to use docker/setup-buildx-action@v4
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/2198c4e05655494fdb4e2ddff12515fd4440cd7d">2198c4e0</a></strong>
<div>
<span> by Endi S. Dewata </span> <i> at 2026-06-18T12:47:19-05:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Update tests to use docker/setup-buildx-action@v7
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/df1f507dbb2478673099959d7ae64e6c50a0825c">df1f507d</a></strong>
<div>
<span> by Endi S. Dewata </span> <i> at 2026-06-22T13:24:00-05:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Update tests to use lewagon/wait-on-check-action@v1.8.0
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/938858d5264e083d18dc4f93d8297f877baa6dff">938858d5</a></strong>
<div>
<span> by Endi S. Dewata </span> <i> at 2026-06-23T09:02:55-05:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Update tests to use actions/setup-java@v5
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/4d1a4b7c9a2182e88324b13727a895077620ca87">4d1a4b7c</a></strong>
<div>
<span> by Endi S. Dewata </span> <i> at 2026-06-23T10:43:51-05:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Update tests to use docker/login-action@v4
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/50772d66fc8c62618d82fde74c39d5998ddd1ddc">50772d66</a></strong>
<div>
<span> by Endi S. Dewata </span> <i> at 2026-06-23T15:49:22-05:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Update tests to use actions/upload-artifact@v7
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/d9345d51e2639a34249dfc653c8dd1c567b9f381">d9345d51</a></strong>
<div>
<span> by Marco Fargetta </span> <i> at 2026-07-24T18:32:44+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Validate PK11Context before use in PK11Cipher native calls
JSS_PK11_getCipherContext extracted the PK11Context pointer from a
CipherContextProxy without checking it for NULL, unlike the analogous
JSS_PK11_getSigContext used by PK11Signature. If the underlying
context was ever invalid (e.g. already released), the NULL pointer
was passed straight into PK11_CipherOp/PK11_DigestFinal, crashing the
whole JVM with a SIGSEGV instead of failing the single operation.
Now a NULL context throws a catchable TokenException at the JSS/NSS
boundary, matching PK11Signature's existing behavior.
Assisted-by: Claude Sonnet 5 <noreply@anthropic.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/b5e5dd754d2068ae2e7ac5226e7f0a333725d4f2">b5e5dd75</a></strong>
<div>
<span> by Marco Fargetta </span> <i> at 2026-07-27T16:29:40+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Remove finalize() from PK11Cipher to prevent premature GC race
PK11Cipher's native methods (updateContext, finalizeContext) are
declared static, so the JVM does not pin the PK11Cipher instance
during JNI execution. Under GC pressure the JIT can determine the
PK11Cipher is unreachable while a static native call is in progress,
triggering finalize() on the finalizer thread. This calls close()
which calls contextProxy.close(), destroying the native PK11Context
and nulling mPointer while the worker thread still holds a JNI
reference to the same CipherContextProxy. The subsequent
JSS_getPtrFromProxy reads NULL, and PK11_DigestFinal(NULL) crashes
with SIGSEGV.
Removing finalize() breaks this chain. Native resource cleanup is
still guaranteed by CipherContextProxy's own NativeProxy.finalize(),
which only runs when the proxy itself is unreachable (no JNI local
refs), so no race is possible. Explicit cleanup via AutoCloseable
close() is preserved.
Assisted-by: Claude Opus 4.6 <noreply@anthropic.com>
</pre>
</li>
<li>
<strong style="font-weight: 600;"><a href="https://salsa.debian.org/freeipa-team/jss/-/commit/5d141d57f04095b1100e4eececca46fa980117fc">5d141d57</a></strong>
<div>
<span> by Marco Fargetta </span> <i> at 2026-07-28T18:04:07+02:00 </i>
</div>
<pre class="commit-message" style='white-space: pre-wrap; display: block; font-size: 14px; color: #3a383f; position: relative; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospace; font-variant-ligatures: none; word-break: break-all; word-wrap: break-word; background-color: #fbfafd; border-radius: 2px; margin: 0; padding: 8px 12px; border: 1px solid #dcdcde;'>Updating version to v5.10.1
</pre>
</li>
</ul>
<h4 style="margin-top: 10px; margin-bottom: 10px;">
143 changed files:
</h4>
<ul>
<li class="file-stats">
<a href="#45dd6ae68bbab2aa0c25915703946c41a90426ab">
.github/workflows/build-tests.yml
</a>
</li>
<li class="file-stats">
<a href="#fe77d5d1439f26e353a42bbd38dece2467ff6558">
.github/workflows/build.yml
</a>
</li>
<li class="file-stats">
<a href="#300e83ffb511c2255d6fa445d2d5ab9ac5221ca7">
.github/workflows/code-analysis-pull.yml
</a>
</li>
<li class="file-stats">
<a href="#0efd20854b65fbb9dc77808a85eb8ef282eea6d4">
.github/workflows/code-analysis.yml
</a>
</li>
<li class="file-stats">
<a href="#cc77230dff021a935d4bbcf8a06b71310c221562">
.github/workflows/external-application-connection-tests.yml
</a>
</li>
<li class="file-stats">
<a href="#b2187c845b4c7703089d25a2365c76aa612505b4">
.github/workflows/known_failures.yml
</a>
</li>
<li class="file-stats">
<a href="#4acb09048a1509dc0c145cd94124306557a9f5f5">
.github/workflows/pkcs11-tests.yml
</a>
</li>
<li class="file-stats">
<a href="#db624a1c44c913dc4357b650289b40b4f3017f7f">
.github/workflows/pki-build-test.yml
</a>
</li>
<li class="file-stats">
<a href="#043a2884f8c091abe1de785578e89de10e5dae72">
.github/workflows/pki-ca-test.yml
</a>
</li>
<li class="file-stats">
<a href="#b942be00021967a6d08f5effdd1123159d59ba73">
.github/workflows/pki-tests.yml
</a>
</li>
<li class="file-stats">
<a href="#982ca828a8ebd164626af77e87d1762e26c1d8a0">
.github/workflows/pki-tools-test.yml
</a>
</li>
<li class="file-stats">
<a href="#41c78cdfdff12c4a101b07b35137b8d117b3b75f">
.github/workflows/pki-tps-test.yml
</a>
</li>
<li class="file-stats">
<a href="#4639989a2b9ca33671669f3e377b9d0308553f80">
.github/workflows/publish.yml
</a>
</li>
<li class="file-stats">
<a href="#6634e674e2e98171d0ea1e1acedb9fb696a5ce56">
.github/workflows/tomcat-basic-test.yml
</a>
</li>
<li class="file-stats">
<a href="#0ac0b983ac189b31591eef57c9e1b8a4981098e7">
.github/workflows/tomcat-https-ciphers-test.yml
</a>
</li>
<li class="file-stats">
<a href="#4a65993676d66267e1993bfe8194c2b9426dcc6a">
.github/workflows/tomcat-https-default-test.yml
</a>
</li>
<li class="file-stats">
<a href="#89cebd280c090d37948fc9832a042cd37c9dea66">
.github/workflows/tomcat-https-multi-certificate-test.yml
</a>
</li>
<li class="file-stats">
<a href="#a457c499f2b9c6aedeeff2125fbeaa2b4263ce96">
.github/workflows/tomcat-https-tls13-test.yml
</a>
</li>
<li class="file-stats">
<a href="#a0a4e24f2b814d1f708ec05ef552345379f5334c">
.github/workflows/tomcat-tests.yml
</a>
</li>
<li class="file-stats">
<a href="#9a2aa4db38d3115ed60da621e012c0efc0172aae">
CMakeLists.txt
</a>
</li>
<li class="file-stats">
<a href="#8ec9a00bfd09b3190ac6b22251dbb1aa95a0579d">
README.md
</a>
</li>
<li class="file-stats">
<a href="#40ebc6823f24f296c0cd3fddd6ccda69b74ff2e4">
azure-pipelines.yml
</a>
</li>
<li class="file-stats">
<a href="#6938ebfea762ce0c7ba0c2da2004eb53baa6e9a4">
base/pom.xml
</a>
</li>
<li class="file-stats">
<a href="#49b65c50c8601d2e1935fd1c58ce4a5ed891704a">
base/src/main/java/org/mozilla/jss/CryptoManager.java
</a>
</li>
<li class="file-stats">
<a href="#57b8141f758fdaf71fb44b9cb305a8563885ed99">
base/src/main/java/org/mozilla/jss/JSSProvider.java
</a>
</li>
<li class="file-stats">
<a href="#8aa50858a0f9e631c07df0ccd181208304ab0229">
base/src/main/java/org/mozilla/jss/asn1/OBJECT_IDENTIFIER.java
</a>
</li>
<li class="file-stats">
<a href="#fa6071a6fa602c46b511915250bea8ebe175d269">
base/src/main/java/org/mozilla/jss/crypto/Algorithm.java
</a>
</li>
<li class="file-stats">
<a href="#b38865b5140616740589da3a54388b79567745a7">
base/src/main/java/org/mozilla/jss/crypto/EncryptionAlgorithm.java
</a>
</li>
<li class="file-stats">
<a href="#c690dcaf5939f0fdc9232d4e271a3513a5c95182">
<span class="new-file">
+
base/src/main/java/org/mozilla/jss/crypto/KEMAlgorithm.java
</span>
</a>
</li>
<li class="file-stats">
<a href="#017fd3f305e3d1738d3600866c3d68795cf32be8">
base/src/main/java/org/mozilla/jss/crypto/KeyPairAlgorithm.java
</a>
</li>
<li class="file-stats">
<a href="#7766c3cc3c9fbf9fa912c30dc0700a8ac4f89a64">
base/src/main/java/org/mozilla/jss/crypto/PrivateKey.java
</a>
</li>
<li class="file-stats">
<a href="#aaecf05142fcf57a2beb03a3c269a03a17daf1c6">
base/src/main/java/org/mozilla/jss/crypto/SignatureAlgorithm.java
</a>
</li>
<li class="file-stats">
<a href="#3bf90378250f2da9ee9174766c729bdd89ac0652">
base/src/main/java/org/mozilla/jss/netscape/security/pkcs/PKCS12Util.java
</a>
</li>
<li class="file-stats">
<a href="#6c4f2d182f8a88c3f4c3db8a1000d4fb0f9ab19d">
base/src/main/java/org/mozilla/jss/netscape/security/pkcs/PKCS7.java
</a>
</li>
<li class="file-stats">
<a href="#33c8eb5a5f5f59e035a4a60da7cba2e1462c3681">
base/src/main/java/org/mozilla/jss/netscape/security/pkcs/PKCS9Attribute.java
</a>
</li>
<li class="file-stats">
<a href="#84f1b7fb4c812c7ffc7b20a662c9747b5c236162">
base/src/main/java/org/mozilla/jss/netscape/security/pkcs/PKCS9Attributes.java
</a>
</li>
<li class="file-stats">
<a href="#5e9967f4acb68ea661eae99eab4522c61ae16623">
base/src/main/java/org/mozilla/jss/netscape/security/util/Cert.java
</a>
</li>
<li class="file-stats">
<a href="#cc867058e7eec72f232a35fd031a3d2afd0a773b">
base/src/main/java/org/mozilla/jss/netscape/security/x509/AlgorithmId.java
</a>
</li>
<li class="file-stats">
<a href="#a7a1d58a3e1ac2bf1c6f3440f26d1d19ff7fef9d">
base/src/main/java/org/mozilla/jss/netscape/security/x509/DirStrConverter.java
</a>
</li>
<li class="file-stats">
<a href="#a279164f87e5ca3ab3066df0f9d5b8374257b9b1">
base/src/main/java/org/mozilla/jss/pkcs11/KeyType.java
</a>
</li>
<li class="file-stats">
<a href="#31235c3b5d6c0f7d4f4679d75847f92ea9e6384e">
base/src/main/java/org/mozilla/jss/pkcs11/PK11Cipher.java
</a>
</li>
<li class="file-stats">
<a href="#5b9643f432bf81a03ee0a8fe1081d14f64fb20d0">
<span class="new-file">
+
base/src/main/java/org/mozilla/jss/pkcs11/PK11DSAParams.java
</span>
</a>
</li>
<li class="file-stats">
<a href="#050775057f62e212aed79c272f5b3f176000deba">
base/src/main/java/org/mozilla/jss/pkcs11/PK11DSAPrivateKey.java
</a>
</li>
<li class="file-stats">
<a href="#af1768075cf18894d5466bef986bce006ddcfed2">
base/src/main/java/org/mozilla/jss/pkcs11/PK11KeyPairGenerator.java
</a>
</li>
<li class="file-stats">
<a href="#429a1df53e70885e9bb548143239b8687603d60e">
base/src/main/java/org/mozilla/jss/pkcs11/PK11KeyWrapper.java
</a>
</li>
<li class="file-stats">
<a href="#1f612733a20c465a539711069d7a45adb1aa2a24">
base/src/main/java/org/mozilla/jss/pkcs11/PK11PrivKey.java
</a>
</li>
<li class="file-stats">
<a href="#a92812db4ff09a1d95b26e006bd64f698955e1ab">
base/src/main/java/org/mozilla/jss/pkcs11/PKCS11Constants.java
</a>
</li>
<li class="file-stats">
<a href="#f7a958337546a5bf0029a24d3fb0213aea91328d">
base/src/main/java/org/mozilla/jss/pkcs12/MacData.java
</a>
</li>
<li class="file-stats">
<a href="#01ee07dbec5e1909c364ff9a2ca9dee9684ec06e">
<span class="new-file">
+
base/src/main/java/org/mozilla/jss/pkcs12/MacType.java
</span>
</a>
</li>
<li class="file-stats">
<a href="#97e4323e65a2459637251d214c183212e496d306">
base/src/main/java/org/mozilla/jss/pkcs12/PFX.java
</a>
</li>
<li class="file-stats">
<a href="#d22da9154b02ef9fa24a23f727fa2d3805a16a3c">
base/src/main/java/org/mozilla/jss/pkix/cms/SignerInfo.java
</a>
</li>
<li class="file-stats">
<a href="#b8c53e676a8ce38cce936e05c4bdd08afeb42e59">
<span class="new-file">
+
base/src/main/java/org/mozilla/jss/pkix/primitive/PBMAC1Params.java
</span>
</a>
</li>
<li class="file-stats">
<a href="#7c06cf0be6e457cacfe602a83c8aa3ca57ed4b4f">
base/src/main/java/org/mozilla/jss/provider/java/security/JSSKeyPairGeneratorSpi.java
</a>
</li>
<li class="file-stats">
<a href="#52b92575ec549e65064e16517afb0b9383bd7740">
base/src/main/java/org/mozilla/jss/provider/java/security/JSSSignatureSpi.java
</a>
</li>
<li class="file-stats">
<a href="#3c4c8746370475d341ff6da8619d9b3320f1bf36">
<span class="new-file">
+
base/src/main/java/org/mozilla/jss/provider/javax/crypto/JSSKEMDecapsulatorSpi.java
</span>
</a>
</li>
<li class="file-stats">
<a href="#7ea37857c84bdabde3356b491db5486ed75f9c50">
<span class="new-file">
+
base/src/main/java/org/mozilla/jss/provider/javax/crypto/JSSKEMEncapsulatorSpi.java
</span>
</a>
</li>
<li class="file-stats">
<a href="#7479f4de66f52ce52ce5e045dfc0eb9b96aa9d73">
<span class="new-file">
+
base/src/main/java/org/mozilla/jss/provider/javax/crypto/JSSKEMSpi.java
</span>
</a>
</li>
<li class="file-stats">
<a href="#173d66e59f6a0f6cfc9147328109aa6d53607e15">
base/src/main/java/org/mozilla/jss/ssl/javax/JSSEngine.java
</a>
</li>
<li class="file-stats">
<a href="#9f7a344d07bf83b97a18088a8699483e9d8b3877">
base/src/main/java/org/mozilla/jss/ssl/javax/JSSEngineReferenceImpl.java
</a>
</li>
<li class="file-stats">
<a href="#6494e2eef51b4b21f61a6b2d48ae50189c7ef0af">
base/src/main/java/org/mozilla/jss/ssl/javax/JSSSession.java
</a>
</li>
<li class="file-stats">
<a href="#a08ac6c39fd2d82cd8d5be3807234c98d47c5ea9">
base/src/main/java/org/mozilla/jss/util/Password.java
</a>
</li>
<li class="file-stats">
<a href="#3fffbfe46c8e86c02169ad00c48114c57f670aef">
base/src/test/java/org/mozilla/jss/tests/BMPStringTest.java
</a>
</li>
<li class="file-stats">
<a href="#a40082cf0dd1a8521fe129c609befc11bac847f2">
base/src/test/java/org/mozilla/jss/tests/ChainSortingTest.java
</a>
</li>
<li class="file-stats">
<a href="#94b1b26a0c58dbea966c9321d8a60b9d183159c3">
base/src/test/java/org/mozilla/jss/tests/GenerateTestCert.java
</a>
</li>
<li class="file-stats">
<a href="#f11b3aba39927fd83dea45c7b60995bc978cb94d">
base/src/test/java/org/mozilla/jss/tests/GenericValueConverterTest.java
</a>
</li>
<li class="file-stats">
<a href="#a4c23454a9777f8c185d238fa1ff79da74ad8cbd">
base/src/test/java/org/mozilla/jss/tests/IA5StringConverterTest.java
</a>
</li>
<li class="file-stats">
<a href="#126f20a07de596fbd1f8ca2fbd9def9c21c4cadf">
base/src/test/java/org/mozilla/jss/tests/IA5StringTest.java
</a>
</li>
<li class="file-stats">
<a href="#129c3373ad14a3c4e50bf94118bb6a03f359cbfe">
base/src/test/java/org/mozilla/jss/tests/JCASigTest.java
</a>
</li>
<li class="file-stats">
<a href="#5e7387d93d5312036969e9e34fff848699ecae1d">
<span class="new-file">
+
base/src/test/java/org/mozilla/jss/tests/KeyEncapsulating.java
</span>
</a>
</li>
<li class="file-stats">
<a href="#3812556f3fa8e2d8abbf08facc086a72424ecb56">
<span class="new-file">
+
base/src/test/java/org/mozilla/jss/tests/MLKEMKeyWrapping.java
</span>
</a>
</li>
<li class="file-stats">
<a href="#cfe918d5fe302aa20549a1e9b78b5d950367e309">
<span class="new-file">
+
base/src/test/java/org/mozilla/jss/tests/PBMAC1Test.java
</span>
</a>
</li>
<li class="file-stats">
<a href="#0b84b91b5bb4da97ff2813ff0213f3bf75a17352">
base/src/test/java/org/mozilla/jss/tests/PrintableConverterTest.java
</a>
</li>
<li class="file-stats">
<a href="#4676228011d0a746e7259dd7644ca8ca5a004574">
base/src/test/java/org/mozilla/jss/tests/PrintableStringTest.java
</a>
</li>
<li class="file-stats">
<a href="#46c208feb89c6d746a70e38afb81dcd5aa7b26aa">
base/src/test/java/org/mozilla/jss/tests/TeletexStringTest.java
</a>
</li>
<li class="file-stats">
<a href="#b87e6b562d0ad00ade95c68ba3b76a994d9e7b9d">
base/src/test/java/org/mozilla/jss/tests/TestKeyGen.java
</a>
</li>
<li class="file-stats">
<a href="#136aabc43e8c8c53ed6e951a4f3bac5a30e61f3b">
<span class="deleted-file">
−
base/src/test/java/org/mozilla/jss/tests/TestPKCS11Constants.java
</span>
</a>
</li>
<li class="file-stats">
<a href="#ed44ea163451f9ebf46918c7d1554d45d991e823">
base/src/test/java/org/mozilla/jss/tests/TestSSLEngine.java
</a>
</li>
<li class="file-stats">
<a href="#8a52a6c69133edee5b5fd106b1811a26b0c2cab7">
base/src/test/java/org/mozilla/jss/tests/UTF8StringTest.java
</a>
</li>
<li class="file-stats">
<a href="#789b635bf83370344f0d445bc4e816efda269b82">
base/src/test/java/org/mozilla/jss/tests/UniversalStringTest.java
</a>
</li>
<li class="file-stats">
<a href="#59f81c123b3abbcb97274545796dd18706c3e106">
build.sh
</a>
</li>
<li class="file-stats">
<a href="#9476b08a5c3527067a65d63cb640555273d0ea4a">
cmake/JSSCommon.cmake
</a>
</li>
<li class="file-stats">
<a href="#9f3af9fef0e3976107ab469d0eb1c9684c9aa796">
cmake/JSSConfig.cmake
</a>
</li>
<li class="file-stats">
<a href="#a8a567af8ceb46f449dc0e7aaaf4ce0465d01d9e">
cmake/JSSTests.cmake
</a>
</li>
<li class="file-stats">
<a href="#0503d1a4d09e68e2f2242a23a3e0a9e4dbe4eef7">
cmake/Java.cmake
</a>
</li>
<li class="file-stats">
<a href="#b8e3e362b5503969f3c0000a19fcf0b78fc91300">
docs/changes/v5.9.0/Algorithm-Changes.adoc
</a>
</li>
<li class="file-stats">
<a href="#e0508355790d59687aba2ecef49584ad5a5fae9c">
docs/legacy_building.md
</a>
</li>
<li class="file-stats">
<a href="#21fff316a47ba3e7a99901dba075eb4ffe04a77c">
docs/pkcs11_constants.md
</a>
</li>
<li class="file-stats">
<a href="#54910b10227c5169852c980ec6d5694e0d2eb9c6">
examples/pom.xml
</a>
</li>
<li class="file-stats">
<a href="#063bf4b6263fbc45f86d361246396c742b514a97">
jss.spec
</a>
</li>
<li class="file-stats">
<a href="#b12d4bb39e2227abf2936f0537fc380e566dcdc9">
lib/jss.map
</a>
</li>
<li class="file-stats">
<a href="#4539f9dee5f5c4745441e141827c0549f44e945b">
native/pom.xml
</a>
</li>
<li class="file-stats">
<a href="#fa1caed4aa5d4ffca9f0218cd238ff2870faade4">
native/src/main/native/org/mozilla/jss/PK11Finder.c
</a>
</li>
<li class="file-stats">
<a href="#8cc5fbdeb910e05722f61226da48912735fbff8e">
native/src/main/native/org/mozilla/jss/crypto/Algorithm.c
</a>
</li>
<li class="file-stats">
<a href="#34e012ca703c1eef1d6bf2db38ab02a78eb3017c">
native/src/main/native/org/mozilla/jss/crypto/Algorithm.h
</a>
</li>
<li class="file-stats">
<a href="#40f55644cc5430ffd9d30372ce07f4831ef13dcc">
native/src/main/native/org/mozilla/jss/crypto/JSSOAEPParameterSpec.c
</a>
</li>
<li class="file-stats">
<a href="#945c29b99b03ad58ab3587b8be34ddd5cb64841b">
native/src/main/native/org/mozilla/jss/crypto/KBKDF.c
</a>
</li>
<li class="file-stats">
<a href="#8f3e60f15261e4efe8d1ad32f0b7aef742fa22d2">
native/src/main/native/org/mozilla/jss/pkcs11/PK11Cipher.c
</a>
</li>
<li class="file-stats">
<a href="#8a09dfb0ea507bcb08d255ac3c311b82ce28f06c">
native/src/main/native/org/mozilla/jss/pkcs11/PK11KeyGenerator.c
</a>
</li>
<li class="file-stats">
<a href="#072407adb83919cfe96273f3041ecfab8e836fd5">
native/src/main/native/org/mozilla/jss/pkcs11/PK11KeyPairGenerator.c
</a>
</li>
<li class="file-stats">
<a href="#9791ffc067685992239f5a629b4ad0c08b010e2d">
native/src/main/native/org/mozilla/jss/pkcs11/PK11KeyWrapper.c
</a>
</li>
<li class="file-stats">
<a href="#ff5749d5d972b674aafce9eb996de6bdda7fa3cf">
native/src/main/native/org/mozilla/jss/pkcs11/PK11PrivKey.c
</a>
</li>
<li class="file-stats">
<a href="#b22cdd6f48a965fe83a0111abd21187a61d90e8f">
native/src/main/native/org/mozilla/jss/pkcs11/PK11PubKey.c
</a>
</li>
<li class="file-stats">
<a href="#57b9bdfa2a0e29e53e211a349b267d5d878cf7b5">
native/src/main/native/org/mozilla/jss/pkcs11/PK11Store.c
</a>
</li>
<li class="file-stats">
<a href="#caf65740fdb91863dfe77f7cbf9d8ff576096d28">
<span class="new-file">
+
native/src/main/native/org/mozilla/jss/provider/javax/crypto/JSSKEMDecapsulatorSpi.c
</span>
</a>
</li>
<li class="file-stats">
<a href="#88c101127d59372ed272abf65010b98ac7cc32ce">
<span class="new-file">
+
native/src/main/native/org/mozilla/jss/provider/javax/crypto/JSSKEMEncapsulatorSpi.c
</span>
</a>
</li>
<li class="file-stats">
<a href="#ed62af7a2c5da39f5cd7530ffeb3039e01e83e1c">
native/src/main/native/org/mozilla/jss/ssl/SSLCipher.c
</a>
</li>
<li class="file-stats">
<a href="#1c7d4b15fb0915c1bbb6840db6102df7983dd27e">
native/src/main/native/org/mozilla/jss/util/java_ids.h
</a>
</li>
<li class="file-stats">
<a href="#559aefee99208a375936f41725923913b2ea004d">
native/src/main/native/org/mozilla/jss/util/jssutil.c
</a>
</li>
<li class="file-stats">
<a href="#be91d69af08b793251fe510be8e102310f242bcc">
native/src/main/native/org/mozilla/jss/util/jssver.h.in
</a>
</li>
<li class="file-stats">
<a href="#442292b8a7efeabbe4cc176709b833b1792140ec">
pom.xml
</a>
</li>
<li class="file-stats">
<a href="#a470c7bee955113786391d8b7f40487514b0699b">
revert_update_version.sh
</a>
</li>
<li class="file-stats">
<a href="#b750ac9f0d57eb4d29ecc591868aaf008e8f06c1">
symkey/pom.xml
</a>
</li>
<li class="file-stats">
<a href="#c62acf655db1fd8dac93c7ebc9513169f38bcabb">
symkey/src/main/native/org/mozilla/jss/symkey/SessionKey.cpp
</a>
</li>
<li class="file-stats">
<a href="#78f669976e0ea4b280cdca274a05e8184b645d83">
symkey/src/main/native/org/mozilla/jss/symkey/SymKey.cpp
</a>
</li>
<li class="file-stats">
<a href="#c98417d706c045433f4a14001a4fc5564ab8a8f7">
tests/bin/ds-artifacts-save.sh
</a>
</li>
<li class="file-stats">
<a href="#32df0460cf2cf5b92229e700497b87dc238c4dda">
tests/bin/ds-create.sh
</a>
</li>
<li class="file-stats">
<a href="#b0d5cbb1ac6cd3573ea65223e09333c048e736ac">
tests/bin/ds-remove.sh
</a>
</li>
<li class="file-stats">
<a href="#55b5bff8c5d54e23ddff8f412cb89137c7f94934">
tests/bin/ds-start.sh
</a>
</li>
<li class="file-stats">
<a href="#4234907bdb1e4fab4c587518e1c790e76cd91d1a">
tests/bin/ds-stop.sh
</a>
</li>
<li class="file-stats">
<a href="#0ed823c736dd9f9e910c22c9429955d8e516cab3">
tests/bin/pki-artifacts-save.sh
</a>
</li>
<li class="file-stats">
<a href="#fdfdca45963a40219d64fbcda4e25def97ffa796">
tests/bin/rpminspect.sh
</a>
</li>
<li class="file-stats">
<a href="#0023652ca2e7f0d52029775e387facd40d321ddf">
tests/bin/runner-init.sh
</a>
</li>
<li class="file-stats">
<a href="#b960b93ee0e659a43ebfe4edae96397e2b1f8527">
<span class="new-file">
+
tests/bin/test-init.sh
</span>
</a>
</li>
<li class="file-stats">
<a href="#5284d806878e7e8a3eb231f6252ba7e000f6ce65">
tests/bin/tomcat-start-wait.sh
</a>
</li>
<li class="file-stats">
<a href="#a71983a808796cb6af4027f0d15a5e91a85d2102">
tomcat-10.1/pom.xml
</a>
</li>
<li class="file-stats">
<a href="#9e0d824e899e26906b0f33a03d5855b1d46db91e">
tomcat-10.1/src/main/java/org/dogtagpki/jss/tomcat/JSSContext.java
</a>
</li>
<li class="file-stats">
<a href="#b776daf8b1be2fad3f70e50d38e6974c85badde2">
tomcat-10.1/src/main/java/org/dogtagpki/jss/tomcat/JSSNioEndpoint.java
</a>
</li>
<li class="file-stats">
<a href="#349a5a569ab2caa173ddec3b8cc6d16b09b1bff4">
tomcat-10.1/src/main/java/org/dogtagpki/jss/tomcat/JSSSecureNioChannel.java
</a>
</li>
<li class="file-stats">
<a href="#8b4dee5ab9780fef174402f828faee779e0aba83">
tomcat-9.0/pom.xml
</a>
</li>
<li class="file-stats">
<a href="#290be4391a9ffe4630e3fc53789c809b1705f3af">
tomcat/pom.xml
</a>
</li>
<li class="file-stats">
<a href="#55a27ed65e546100889216a6d7fcf460a2ffca8b">
tools/Dockerfiles/fedora_rawhide
</a>
</li>
<li class="file-stats">
<a href="#7677598a6373740d0a7d37dbd01136a26eafeeab">
tools/common_roots.sh
</a>
</li>
<li class="file-stats">
<a href="#a2608b459d07e86995e6d9f69f0da6b2d7d79123">
tools/reproducible_jar.sh
</a>
</li>
<li class="file-stats">
<a href="#5847241c7c2bbf622a913d86fb6f63484be8dc51">
tools/run_container.sh
</a>
</li>
<li class="file-stats">
<a href="#eeceded2f417aecf3b77fba143092ecbda77ebce">
tools/run_test.sh.in
</a>
</li>
<li class="file-stats">
<a href="#afbfdc3b4bf3f5023888720cb785d11672c66cf1">
tools/src/main/native/p12tool/p12tool.c
</a>
</li>
<li class="file-stats">
<a href="#b9fb41b00d0bc66f6fc75f251c59e89482910a92">
tools/src/main/native/p12tool/p12tool.h
</a>
</li>
<li class="file-stats">
<a href="#05632132886a0ff3d7bf90e45d77cf49b9d03aca">
tools/src/main/native/p12tool/secutil.h
</a>
</li>
<li class="file-stats">
<a href="#c71ecca02c4e5539dcfad89ce6cded84ff6a38d1">
tools/src/main/native/p7tool/p7tool.c
</a>
</li>
<li class="file-stats">
<a href="#bb9011a5c0b679d02d2d148dd55dded40fa3210c">
tools/src/main/native/p7tool/secpwd.c
</a>
</li>
<li class="file-stats">
<a href="#63058571ed5ca5a1ac008adf5a15112ebcf0f99d">
tools/src/main/native/p7tool/secutil.c
</a>
</li>
<li class="file-stats">
<a href="#5d8fe1063ebe5d2f5544ae148dbf61fb7b14641a">
tools/src/main/native/sslget/sslget.c
</a>
</li>
<li class="file-stats">
<a href="#a91c079915881997214fbfc43d3f3563b6fe7849">
update_version.sh
</a>
</li>
</ul>
<h5 style="margin-top: 10px; margin-bottom: 10px; font-size: .875rem;">
The diff was not included because it is too large.
</h5>
</div>
<div class="footer" style="margin-top: 10px;">
<p style="font-size: small; color: #626168;">
—
<br>
<a href="https://salsa.debian.org/freeipa-team/jss/-/compare/814f94a5e3127f3a8211204be283e66c347e9fb6...5d141d57f04095b1100e4eececca46fa980117fc">View it on GitLab</a>.
<br>
You're receiving this email because of your account on <a target="_blank" rel="noopener noreferrer" href="https://salsa.debian.org">salsa.debian.org</a>. <a href="https://salsa.debian.org/-/profile/notifications" target="_blank" rel="noopener noreferrer" class="mng-notif-link">Manage all notifications</a> · <a href="https://salsa.debian.org/help" target="_blank" rel="noopener noreferrer" class="help-link">Help</a>
<span style="color: transparent; font-size: 0; display: none; overflow: hidden; opacity: 0; width: 0; height: 0; max-width: 0; max-height: 0;">
Notification message regarding https://salsa.debian.org/freeipa-team/jss/-/compare/814f94a5e3127f3a8211204be283e66c347e9fb6...5d141d57f04095b1100e4eececca46fa980117fc at 1790492710
</span>
</p>
</div>
</body>
</html>