jdk-24/jdk/test/sun/security/pkcs11
Valerie Peng fcb924e751 8130648: JCK test api/java_security/AuthProvider/ProviderTests_login starts failing after JDK-7191662
Make uninitialized SunPKCS11 provider throw IllegalStateException for AuthProvider calls.

Reviewed-by: mullan
2015-10-08 20:51:08 +00:00
..
Cipher 8078334: Mark regression tests using randomness 2015-04-29 10:25:53 -07:00
ec 8133318: Exclude intermittent failing PKCS11 tests on Solaris SPARC 11.1 and earlier 2015-08-12 14:38:09 +01:00
fips 8081347: Add @modules to jdk_core tests 2015-05-28 10:54:48 -07:00
KeyAgreement 7146728: Inconsistent length for the generated secret using DH key agreement impl from SunJCE and PKCS11 2012-03-20 15:06:13 -07:00
KeyGenerator 8078334: Mark regression tests using randomness 2015-04-29 10:25:53 -07:00
KeyPairGenerator 7196382: PKCS11 provider should support 2048-bit DH 2013-10-08 11:07:31 -07:00
KeyStore 7191662: JCE providers should be located via ServiceLoader 2015-06-26 21:34:34 +00:00
Mac 8078334: Mark regression tests using randomness 2015-04-29 10:25:53 -07:00
MessageDigest 8078334: Mark regression tests using randomness 2015-04-29 10:25:53 -07:00
nss 8059627: Enable PKCS11 tests on Mac 2014-10-06 16:44:57 +01:00
Provider 8130648: JCK test api/java_security/AuthProvider/ProviderTests_login starts failing after JDK-7191662 2015-10-08 20:51:08 +00:00
rsa 8133318: Exclude intermittent failing PKCS11 tests on Solaris SPARC 11.1 and earlier 2015-08-12 14:38:09 +01:00
Secmod 8048622: Enhance tests for PKCS11 keystores with NSS 2015-09-14 19:54:58 +03:00
SecureRandom 8078334: Mark regression tests using randomness 2015-04-29 10:25:53 -07:00
Serialize 6943119: Rebrand source copyright notices 2010-05-25 15:58:33 -07:00
Signature 8133318: Exclude intermittent failing PKCS11 tests on Solaris SPARC 11.1 and earlier 2015-08-12 14:38:09 +01:00
sslecc 8076328: Enforce key exchange constraints 2015-04-22 05:09:54 +00:00
tls 8081347: Add @modules to jdk_core tests 2015-05-28 10:54:48 -07:00
PKCS11Test.java 8048622: Enhance tests for PKCS11 keystores with NSS 2015-09-14 19:54:58 +03:00
README 8020424: The NSS version should be detected before running crypto tests 2013-07-29 13:43:24 -07:00
SampleTest.java 6943119: Rebrand source copyright notices 2010-05-25 15:58:33 -07:00
SecmodTest.java 8029235: Update copyright year to match last edit in jdk8 jdk repository for 2013 2013-12-26 12:04:16 -08:00

This README is to keep a list facts and known workaround for the pkcs11 java tests
perform as a result of bugs or features in NSS or other pkcs11 libraries.

- NSS ECC None/Basic/Extended
The tests detect the NSS library support for Elliptic Curves as to not
report incorrect failures.  PKCS11 reports back CKR_DOMAIN_PARAMS_INVALID
when the curve is not supported.

- Default libsoftokn3.so
By default PKCS11Test.java will look for libsoftokn3.so.  There are a number of
tests, particularly in Secmod, that need libnss3.so.  The method useNSS() in
PKCS11test.java is to change the search and version checking to libnss3.

ECC Basic supports is secp256r1, secp384r1, and secp521r1.

- A bug in NSS 3.12 (Mozilla bug 471665) causes AES key lengths to be
read incorrectly. KeyStore/SecretKeysBasic.java tiggers this bug and
knows to avoid it.

- A number of EC tests fail because of a DER bug in NSS 3.11.  The best guess
is Mozilla bug 480280.  Those tests that abort execution with a PASS result
are:  TestECDH2, TestECDSA, TestECDSA2 and TestECGenSpec.