f3b2292
--- jdk8/jdk/src/share/classes/com/sun/crypto/provider/DHKeyPairGenerator.java	Tue Mar 17 00:09:12 2015 +0300
f3b2292
+++ jdk8/jdk/src/share/classes/com/sun/crypto/provider/DHKeyPairGenerator.java	Wed Apr 08 14:25:54 2015 +0100
f3b2292
@@ -1,5 +1,6 @@ 
f3b2292
 /*
f3b2292
  * Copyright (c) 1997, 2013, Oracle and/or its affiliates. All rights reserved.
f3b2292
+ * Copyright (c) 2014 Red Hat Inc.
f3b2292
  * DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
f3b2292
  *
f3b2292
  * This code is free software; you can redistribute it and/or modify it
f3b2292
@@ -80,10 +81,10 @@ 
f3b2292
      * @param random the source of randomness
f3b2292
      */
f3b2292
     public void initialize(int keysize, SecureRandom random) {
f3b2292
-        if ((keysize < 512) || (keysize > 2048) || (keysize % 64 != 0)) {
f3b2292
+        if ((keysize < 512) || (keysize > 4096) || (keysize % 64 != 0)) {
f3b2292
             throw new InvalidParameterException("Keysize must be multiple "
f3b2292
                                                 + "of 64, and can only range "
f3b2292
-                                                + "from 512 to 2048 "
f3b2292
+                                                + "from 512 to 4096 "
f3b2292
                                                 + "(inclusive)");
f3b2292
         }
f3b2292
         this.pSize = keysize;
f3b2292
@@ -115,11 +116,11 @@ 
f3b2292
 
f3b2292
         params = (DHParameterSpec)algParams;
f3b2292
         pSize = params.getP().bitLength();
f3b2292
-        if ((pSize < 512) || (pSize > 2048) ||
f3b2292
+        if ((pSize < 512) || (pSize > 4096) ||
f3b2292
             (pSize % 64 != 0)) {
f3b2292
             throw new InvalidAlgorithmParameterException
f3b2292
                 ("Prime size must be multiple of 64, and can only range "
f3b2292
-                 + "from 512 to 2048 (inclusive)");
f3b2292
+                 + "from 512 to 4096 (inclusive)");
f3b2292
         }
f3b2292
 
f3b2292
         // exponent size is optional, could be 0
f3b2292
--- jdk8/jdk/src/share/classes/com/sun/crypto/provider/DHParameterGenerator.java	Tue Mar 17 00:09:12 2015 +0300
f3b2292
+++ jdk8/jdk/src/share/classes/com/sun/crypto/provider/DHParameterGenerator.java	Wed Apr 08 14:25:54 2015 +0100
f3b2292
@@ -1,5 +1,6 @@ 
f3b2292
 /*
f3b2292
  * Copyright (c) 1997, 2013, Oracle and/or its affiliates. All rights reserved.
f3b2292
+ * Copyright (c) 2014 Red Hat Inc.
f3b2292
  * DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
f3b2292
  *
f3b2292
  * This code is free software; you can redistribute it and/or modify it
f3b2292
@@ -60,11 +61,11 @@ 
f3b2292
 
f3b2292
     private static void checkKeySize(int keysize)
f3b2292
         throws InvalidAlgorithmParameterException {
f3b2292
-        if ((keysize != 2048) &&
f3b2292
+        if ((keysize != 2048) && (keysize != 4096) &&
f3b2292
             ((keysize < 512) || (keysize > 1024) || (keysize % 64 != 0))) {
f3b2292
             throw new InvalidAlgorithmParameterException(
f3b2292
                 "Keysize must be multiple of 64 ranging from "
f3b2292
-                + "512 to 1024 (inclusive), or 2048");
f3b2292
+                + "512 to 1024 (inclusive), or 2048, or 4096");
f3b2292
         }
f3b2292
     }
f3b2292
 
f3b2292
--- jdk8/jdk/src/share/classes/sun/security/pkcs11/P11KeyPairGenerator.java	Tue Mar 17 00:09:12 2015 +0300
f3b2292
+++ jdk8/jdk/src/share/classes/sun/security/pkcs11/P11KeyPairGenerator.java	Wed Apr 08 14:25:54 2015 +0100
f3b2292
@@ -278,11 +278,11 @@ 
f3b2292
                     // this restriction is in the spec for DSA
f3b2292
                     // since we currently use DSA parameters for DH as well,
f3b2292
                     // it also applies to DH if no parameters are specified
f3b2292
-                    if ((keySize != 2048) &&
f3b2292
+                    if ((keySize != 2048) && (keySize != 4096) &&
f3b2292
                         ((keySize > 1024) || ((keySize & 0x3f) != 0))) {
f3b2292
                         throw new InvalidAlgorithmParameterException(algorithm +
f3b2292
                             " key must be multiples of 64 if less than 1024 bits" +
f3b2292
-                            ", or 2048 bits");
f3b2292
+                            ", or 2048 bits, or 4096 bits");
f3b2292
                     }
f3b2292
                 }
f3b2292
             }
f3b2292
--- jdk8/jdk/test/com/sun/crypto/provider/KeyAgreement/TestExponentSize.java	Tue Mar 17 00:09:12 2015 +0300
f3b2292
+++ jdk8/jdk/test/com/sun/crypto/provider/KeyAgreement/TestExponentSize.java	Wed Apr 08 14:25:54 2015 +0100
f3b2292
@@ -1,5 +1,6 @@ 
f3b2292
 /*
f3b2292
  * Copyright (c) 2005, 2012, Oracle and/or its affiliates. All rights reserved.
f3b2292
+ * Copyright (c) 2014 Red Hat Inc.
f3b2292
  * DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
f3b2292
  *
f3b2292
  * This code is free software; you can redistribute it and/or modify it
f3b2292
@@ -58,7 +59,7 @@ 
f3b2292
      */
f3b2292
     private enum Sizes {
f3b2292
         two56(256), three84(384), five12(512), seven68(768), ten24(1024),
f3b2292
-        twenty48(2048);
f3b2292
+        twenty48(2048), forty96(4096);
f3b2292
 
f3b2292
         private final int intSize;
f3b2292
         private final BigInteger bigIntValue;
f3b2292
@@ -130,6 +131,19 @@ 
f3b2292
         kp = kpg.generateKeyPair();
f3b2292
         checkKeyPair(kp, Sizes.twenty48, Sizes.five12);
f3b2292
 
f3b2292
+        kpg.initialize(Sizes.forty96.getIntSize());
f3b2292
+        kp = kpg.generateKeyPair();
f3b2292
+        checkKeyPair(kp, Sizes.forty96, Sizes.twenty48);
f3b2292
+
f3b2292
+        publicKey = (DHPublicKey)kp.getPublic();
f3b2292
+        p = publicKey.getParams().getP();
f3b2292
+        g = publicKey.getParams().getG();
f3b2292
+
f3b2292
+        // test w/ all values specified
f3b2292
+        kpg.initialize(new DHParameterSpec(p, g, Sizes.ten24.getIntSize()));
f3b2292
+        kp = kpg.generateKeyPair();
f3b2292
+        checkKeyPair(kp, Sizes.forty96, Sizes.ten24);
f3b2292
+
f3b2292
         System.out.println("OK");
f3b2292
     }
f3b2292
 
f3b2292