Alex Kashchenko 296ea8e
diff --git a/src/share/classes/com/sun/crypto/provider/DHKeyPairGenerator.java b/src/share/classes/com/sun/crypto/provider/DHKeyPairGenerator.java
Alex Kashchenko 296ea8e
--- openjdk/jdk/src/share/classes/com/sun/crypto/provider/DHKeyPairGenerator.java
Alex Kashchenko 296ea8e
+++ openjdk/jdk/src/share/classes/com/sun/crypto/provider/DHKeyPairGenerator.java
Alex Kashchenko 296ea8e
@@ -1,5 +1,6 @@
Alex Kashchenko 296ea8e
 /*
Alex Kashchenko 296ea8e
  * Copyright (c) 1997, 2017, Oracle and/or its affiliates. All rights reserved.
Alex Kashchenko 296ea8e
+ * Copyright (c) 2014 Red Hat Inc.
Alex Kashchenko 296ea8e
  * DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
Alex Kashchenko 296ea8e
  *
Alex Kashchenko 296ea8e
  * This code is free software; you can redistribute it and/or modify it
Alex Kashchenko 296ea8e
@@ -74,10 +75,10 @@
Alex Kashchenko c095f9e
     private static void checkKeySize(int keysize)
Alex Kashchenko c095f9e
             throws InvalidParameterException {
74b02f5
 
Alex Kashchenko c095f9e
-        if ((keysize < 512) || (keysize > 2048) || ((keysize & 0x3F) != 0)) {
Alex Kashchenko c095f9e
+        if ((keysize < 512) || (keysize > 4096) || ((keysize & 0x3F) != 0)) {
Alex Kashchenko c095f9e
             throw new InvalidParameterException(
Alex Kashchenko c095f9e
                     "DH key size must be multiple of 64, and can only range " +
Alex Kashchenko c095f9e
-                    "from 512 to 2048 (inclusive). " +
Alex Kashchenko c095f9e
+                    "from 512 to 4096 (inclusive). " +
Alex Kashchenko c095f9e
                     "The specific key size " + keysize + " is not supported");
74b02f5
         }
Alex Kashchenko c095f9e
     }
Alex Kashchenko 296ea8e
diff --git a/src/share/classes/com/sun/crypto/provider/DHParameterGenerator.java b/src/share/classes/com/sun/crypto/provider/DHParameterGenerator.java
Alex Kashchenko 296ea8e
--- openjdk/jdk/src/share/classes/com/sun/crypto/provider/DHParameterGenerator.java
Alex Kashchenko 296ea8e
+++ openjdk/jdk/src/share/classes/com/sun/crypto/provider/DHParameterGenerator.java
Alex Kashchenko 296ea8e
@@ -1,5 +1,6 @@
Alex Kashchenko 296ea8e
 /*
Alex Kashchenko 296ea8e
  * Copyright (c) 1997, 2017, Oracle and/or its affiliates. All rights reserved.
Alex Kashchenko 296ea8e
+ * Copyright (c) 2014 Red Hat Inc.
Alex Kashchenko 296ea8e
  * DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
Alex Kashchenko 296ea8e
  *
Alex Kashchenko 296ea8e
  * This code is free software; you can redistribute it and/or modify it
Alex Kashchenko 296ea8e
@@ -61,11 +62,11 @@
74b02f5
 
74b02f5
     private static void checkKeySize(int keysize)
Alex Kashchenko c095f9e
             throws InvalidParameterException {
Alex Kashchenko c095f9e
-            if ((keysize != 2048) &&
Alex Kashchenko c095f9e
+            if ((keysize != 2048) && (keysize != 4096) &&
74b02f5
             ((keysize < 512) || (keysize > 1024) || (keysize % 64 != 0))) {
Alex Kashchenko c095f9e
             throw new InvalidParameterException(
Alex Kashchenko c095f9e
                     "DH key size must be multiple of 64 and range " +
Alex Kashchenko c095f9e
-                    "from 512 to 1024 (inclusive), or 2048. " +
Alex Kashchenko c095f9e
+                    "from 512 to 1024 (inclusive), or 2048, or 4096. " +
Alex Kashchenko c095f9e
                     "The specific key size " + keysize + " is not supported");
74b02f5
         }
74b02f5
     }
Alex Kashchenko 296ea8e
diff --git a/src/share/classes/sun/security/pkcs11/P11KeyPairGenerator.java b/src/share/classes/sun/security/pkcs11/P11KeyPairGenerator.java
Alex Kashchenko 296ea8e
--- openjdk/jdk/src/share/classes/sun/security/pkcs11/P11KeyPairGenerator.java
Alex Kashchenko 296ea8e
+++ openjdk/jdk/src/share/classes/sun/security/pkcs11/P11KeyPairGenerator.java
Alex Kashchenko 296ea8e
@@ -292,11 +292,11 @@
74b02f5
                     // this restriction is in the spec for DSA
74b02f5
                     // since we currently use DSA parameters for DH as well,
74b02f5
                     // it also applies to DH if no parameters are specified
74b02f5
-                    if ((keySize != 2048) &&
74b02f5
+                    if ((keySize != 2048) && (keySize != 4096) &&
74b02f5
                         ((keySize > 1024) || ((keySize & 0x3f) != 0))) {
74b02f5
                         throw new InvalidAlgorithmParameterException(algorithm +
74b02f5
                             " key must be multiples of 64 if less than 1024 bits" +
Alex Kashchenko c095f9e
-                            ", or 2048 bits. " +
Alex Kashchenko c095f9e
+                            ", or 2048 bits, or 4096 bits. " +
Alex Kashchenko c095f9e
                             "The specific key size " +
Alex Kashchenko c095f9e
                             keySize + " is not supported");
74b02f5
                     }
Alex Kashchenko 296ea8e
diff --git a/test/com/sun/crypto/provider/KeyAgreement/TestExponentSize.java b/test/com/sun/crypto/provider/KeyAgreement/TestExponentSize.java
Alex Kashchenko 296ea8e
--- openjdk/jdk/test/com/sun/crypto/provider/KeyAgreement/TestExponentSize.java
Alex Kashchenko 296ea8e
+++ openjdk/jdk/test/com/sun/crypto/provider/KeyAgreement/TestExponentSize.java
Alex Kashchenko 296ea8e
@@ -1,5 +1,6 @@
Alex Kashchenko 296ea8e
 /*
Alex Kashchenko 296ea8e
  * Copyright (c) 2005, 2012, Oracle and/or its affiliates. All rights reserved.
Alex Kashchenko 296ea8e
+ * Copyright (c) 2014 Red Hat Inc.
Alex Kashchenko 296ea8e
  * DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
Alex Kashchenko 296ea8e
  *
Alex Kashchenko 296ea8e
  * This code is free software; you can redistribute it and/or modify it
Alex Kashchenko 296ea8e
@@ -58,7 +59,7 @@
74b02f5
      */
74b02f5
     private enum Sizes {
74b02f5
         two56(256), three84(384), five12(512), seven68(768), ten24(1024),
74b02f5
-        twenty48(2048);
74b02f5
+        twenty48(2048), forty96(4096);
74b02f5
 
74b02f5
         private final int intSize;
74b02f5
         private final BigInteger bigIntValue;
Alex Kashchenko 296ea8e
@@ -130,6 +131,19 @@
74b02f5
         kp = kpg.generateKeyPair();
74b02f5
         checkKeyPair(kp, Sizes.twenty48, Sizes.five12);
74b02f5
 
74b02f5
+        kpg.initialize(Sizes.forty96.getIntSize());
74b02f5
+        kp = kpg.generateKeyPair();
74b02f5
+        checkKeyPair(kp, Sizes.forty96, Sizes.twenty48);
74b02f5
+
74b02f5
+        publicKey = (DHPublicKey)kp.getPublic();
74b02f5
+        p = publicKey.getParams().getP();
74b02f5
+        g = publicKey.getParams().getG();
74b02f5
+
74b02f5
+        // test w/ all values specified
74b02f5
+        kpg.initialize(new DHParameterSpec(p, g, Sizes.ten24.getIntSize()));
74b02f5
+        kp = kpg.generateKeyPair();
74b02f5
+        checkKeyPair(kp, Sizes.forty96, Sizes.ten24);
74b02f5
+
74b02f5
         System.out.println("OK");
74b02f5
     }
74b02f5