You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
We have a Spring + jetty client code base communicating over TLS1.3 and HTTP2. We have a use case to export TLS keying material or the master secret. We need this information to further derive keys for JWE tokens ciphering.
The text was updated successfully, but these errors were encountered:
@sanjerai OpenJDK does not provide any API to access the TLS exporters, so there is nothing that Jetty can do.
You may want to open an OpenJDK issue, and I would gladly support this, since it is required also for QUIC+TLS, which is currently not possible to implement using OpenJDK APIs.
Just to set expectations, realize that that issue will be fixed in Java 25 or later, and it will take a while (years) before adoption widespreads, so do not hold your breath 😄
Jetty version(s)
Jetty 11.0.20+
Enhancement Description
RFC5705 defines and RFC8446 updates keying material exporters for TLS:
Many other TLS implementations already support it:
5G mobile specs mandate the use of TLS session at app level for JWE:
We have a Spring + jetty client code base communicating over TLS1.3 and HTTP2. We have a use case to export TLS keying material or the master secret. We need this information to further derive keys for JWE tokens ciphering.
The text was updated successfully, but these errors were encountered: