|
| 1 | +security.provider.1=org.bouncycastle.jcajce.provider.BouncyCastleFipsProvider |
| 2 | +security.provider.2=org.bouncycastle.jsse.provider.BouncyCastleJsseProvider fips:BCFIPS |
| 3 | +security.provider.3=SUN |
| 4 | +security.provider.11=-BC |
| 5 | + |
| 6 | +securerandom.source=file:/dev/random |
| 7 | +securerandom.strongAlgorithms=NativePRNGBlocking:SUN,DRBG:SUN |
| 8 | +securerandom.drbg.config= |
| 9 | + |
| 10 | +login.configuration.provider=sun.security.provider.ConfigFile |
| 11 | + |
| 12 | +policy.provider=sun.security.provider.PolicyFile |
| 13 | +policy.url.1=file:/etc/java/security/java.policy |
| 14 | +policy.expandProperties=true |
| 15 | +policy.allowSystemProperty=true |
| 16 | +policy.ignoreIdentityScope=false |
| 17 | + |
| 18 | +keystore.type=bcfks |
| 19 | +keystore.type.compat=true |
| 20 | + |
| 21 | +package.access=sun.misc.,\ |
| 22 | + sun.reflect. |
| 23 | +package.definition=sun.misc.,\ |
| 24 | + sun.reflect. |
| 25 | + |
| 26 | +security.overridePropertiesFile=true |
| 27 | + |
| 28 | +ssl.KeyManagerFactory.algorithm=PKIX |
| 29 | +ssl.TrustManagerFactory.algorithm=PKIX |
| 30 | + |
| 31 | +networkaddress.cache.negative.ttl=10 |
| 32 | + |
| 33 | +krb5.kdc.bad.policy = tryLast |
| 34 | + |
| 35 | +sun.security.krb5.disableReferrals=false |
| 36 | +sun.security.krb5.maxReferrals=5 |
| 37 | + |
| 38 | +jdk.disabled.namedCurves = secp112r1, secp112r2, secp128r1, secp128r2, \ |
| 39 | + secp160k1, secp160r1, secp160r2, secp192k1, secp192r1, secp224k1, \ |
| 40 | + secp224r1, secp256k1, sect113r1, sect113r2, sect131r1, sect131r2, \ |
| 41 | + sect163k1, sect163r1, sect163r2, sect193r1, sect193r2, sect233k1, \ |
| 42 | + sect233r1, sect239k1, sect283k1, sect283r1, sect409k1, sect409r1, \ |
| 43 | + sect571k1, sect571r1, X9.62 c2tnb191v1, X9.62 c2tnb191v2, \ |
| 44 | + X9.62 c2tnb191v3, X9.62 c2tnb239v1, X9.62 c2tnb239v2, X9.62 c2tnb239v3, \ |
| 45 | + X9.62 c2tnb359v1, X9.62 c2tnb431r1, X9.62 prime192v2, X9.62 prime192v3, \ |
| 46 | + X9.62 prime239v1, X9.62 prime239v2, X9.62 prime239v3, brainpoolP256r1, \ |
| 47 | + brainpoolP320r1, brainpoolP384r1, brainpoolP512r1 |
| 48 | + |
| 49 | +jdk.certpath.disabledAlgorithms=MD2, MD5, \ |
| 50 | + RSA keySize < 1024, DSA keySize < 1024, EC keySize < 224, \ |
| 51 | + SHA1, \ |
| 52 | + secp112r1, secp112r2, secp128r1, secp128r2, \ |
| 53 | + secp160k1, secp160r1, secp160r2, secp192k1, secp192r1, secp224k1, \ |
| 54 | + secp224r1, secp256k1, sect113r1, sect113r2, sect131r1, sect131r2, \ |
| 55 | + sect163k1, sect163r1, sect163r2, sect193r1, sect193r2, sect233k1, \ |
| 56 | + sect233r1, sect239k1, sect283k1, sect283r1, sect409k1, sect409r1, \ |
| 57 | + sect571k1, sect571r1, \ |
| 58 | + brainpoolP256r1, brainpoolP320r1, brainpoolP384r1, brainpoolP512r1 |
| 59 | + |
| 60 | +jdk.security.legacyAlgorithms=SHA1, \ |
| 61 | + RSA keySize < 2048, DSA keySize < 2048 |
| 62 | + |
| 63 | +jdk.jar.disabledAlgorithms=MD2, MD5, RSA keySize < 1024, \ |
| 64 | + DSA keySize < 1024, SHA1, \ |
| 65 | + secp112r1, secp112r2, secp128r1, secp128r2, \ |
| 66 | + secp160k1, secp160r1, secp160r2, secp192k1, secp192r1, secp224k1, \ |
| 67 | + secp224r1, secp256k1, sect113r1, sect113r2, sect131r1, sect131r2, \ |
| 68 | + sect163k1, sect163r1, sect163r2, sect193r1, sect193r2, sect233k1, \ |
| 69 | + sect233r1, sect239k1, sect283k1, sect283r1, sect409k1, sect409r1, \ |
| 70 | + sect571k1, sect571r1, X9.62 c2tnb191v1, X9.62 c2tnb191v2, \ |
| 71 | + X9.62 c2tnb191v3, X9.62 c2tnb239v1, X9.62 c2tnb239v2, X9.62 c2tnb239v3, \ |
| 72 | + X9.62 c2tnb359v1, X9.62 c2tnb431r1, X9.62 prime192v2, X9.62 prime192v3, \ |
| 73 | + X9.62 prime239v1, X9.62 prime239v2, X9.62 prime239v3, brainpoolP256r1, \ |
| 74 | + brainpoolP320r1, brainpoolP384r1, brainpoolP512r1 |
| 75 | + |
| 76 | +jdk.tls.disabledAlgorithms=MD5, SSLv3, TLSv1, TLSv1.1, RC4, DES, MD5withRSA, \ |
| 77 | + DH keySize < 1024, EC keySize < 224, 3DES_EDE_CBC, anon, NULL, \ |
| 78 | + secp112r1, secp112r2, secp128r1, secp128r2, \ |
| 79 | + secp160k1, secp160r1, secp160r2, secp192k1, secp192r1, secp224k1, \ |
| 80 | + secp224r1, secp256k1, sect113r1, sect113r2, sect131r1, sect131r2, \ |
| 81 | + sect163k1, sect163r1, sect163r2, sect193r1, sect193r2, sect233k1, \ |
| 82 | + sect233r1, sect239k1, sect283k1, sect283r1, sect409k1, sect409r1, \ |
| 83 | + sect571k1, sect571r1, brainpoolP256r1, \ |
| 84 | + brainpoolP320r1, brainpoolP384r1, brainpoolP512r1 |
| 85 | +jdk.tls.legacyAlgorithms= \ |
| 86 | + K_NULL, C_NULL, M_NULL, \ |
| 87 | + DH_anon, ECDH_anon, \ |
| 88 | + RC4_128, RC4_40, DES_CBC, DES40_CBC, \ |
| 89 | + 3DES_EDE_CBC |
| 90 | +jdk.tls.keyLimits=AES/GCM/NoPadding KeyUpdate 2^37, \ |
| 91 | + ChaCha20-Poly1305 KeyUpdate 2^37 |
| 92 | + |
| 93 | +crypto.policy=unlimited |
| 94 | + |
| 95 | +jdk.xml.dsig.secureValidationPolicy=\ |
| 96 | + disallowAlg http://www.w3.org/TR/1999/REC-xslt-19991116,\ |
| 97 | + disallowAlg http://www.w3.org/2001/04/xmldsig-more#rsa-md5,\ |
| 98 | + disallowAlg http://www.w3.org/2001/04/xmldsig-more#hmac-md5,\ |
| 99 | + disallowAlg http://www.w3.org/2001/04/xmldsig-more#md5,\ |
| 100 | + maxTransforms 5,\ |
| 101 | + maxReferences 30,\ |
| 102 | + disallowReferenceUriSchemes file http https,\ |
| 103 | + minKeySize RSA 1024,\ |
| 104 | + minKeySize DSA 1024,\ |
| 105 | + minKeySize EC 224,\ |
| 106 | + noDuplicateIds,\ |
| 107 | + noRetrievalMethodLoops |
| 108 | + |
| 109 | +jceks.key.serialFilter = java.base/java.lang.Enum;java.base/java.security.KeyRep;\ |
| 110 | + java.base/java.security.KeyRep$Type;java.base/javax.crypto.spec.SecretKeySpec;!* |
| 111 | + |
| 112 | +jdk.sasl.disabledMechanisms=CRAM-MD5, DIGEST-MD5 |
| 113 | +jdk.security.caDistrustPolicies=SYMANTEC_TLS |
| 114 | +jdk.io.permissionsUseCanonicalPath=false |
| 115 | + |
| 116 | +jdk.tls.alpnCharset=ISO_8859_1 |
| 117 | + |
| 118 | +org.bouncycastle.fips.approved_only=true |
0 commit comments