RHEL crypto policy jdk.tls.ephemeralDHKeySize setting ignored
Issue
- The security scanner flags the application as allowing key sizes < 2048 bits despite the following in
/usr/share/crypto-policies/<POLICY>/java.txt:
jdk.tls.ephemeralDHKeySize=2048
Environment
- Red Hat Enterprise Linux (RHEL)
- 8
- 9
- Red Hat build of OpenJDK
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.