← Knowledge base

Java and JSSE

Cryptographic primitive support and TLS integration are separate features. An ML-KEM KEM implementation does not by itself show that a JSSE provider supports hybrid TLS groups.

Evidence to collect

  1. Record the deployed JDK and security providers.
  2. Consult the JSSE documentation for that release before setting jdk.tls.namedGroups. Unsupported names must not be treated as an upgrade path.
  3. Check the TLS backend actually used by Tomcat, Netty, or your HTTP client.
  4. Collect handshake evidence from the application or server without logging secrets. Record unknown when the selected group is not available.

Read-only inventory

Run this in the environment used by the application. Missing commands mean the tool is unavailable. This output is inventory, not a negotiation result.

java -version

Record the scope and result

Record the tested component, client, peer, protocol, selected algorithm, and date. Keep observed negotiation, documented capability, and unknown distinct. A failed check can reflect local tooling, certificate validation, network policy, or configuration; it does not prove that all PQC is unsupported.

Official references

Guidance reviewed 24 September 2026. Verify documentation for your deployed release; vendor capabilities and defaults change.