Java and JSSE
Cryptographic primitive support and TLS integration are separate features. An ML-KEM KEM implementation does not by itself show that a JSSE provider supports hybrid TLS groups.
Evidence to collect
- Record the deployed JDK and security providers.
- Consult the JSSE documentation for that release before setting jdk.tls.namedGroups. Unsupported names must not be treated as an upgrade path.
- Check the TLS backend actually used by Tomcat, Netty, or your HTTP client.
- Collect handshake evidence from the application or server without logging secrets. Record unknown when the selected group is not available.
Read-only inventory
Run this in the environment used by the application. Missing commands mean the tool is unavailable. This output is inventory, not a negotiation result.
java -versionRecord the scope and result
Record the tested component, client, peer, protocol, selected algorithm, and date. Keep observed negotiation, documented capability, and unknown distinct. A failed check can reflect local tooling, certificate validation, network policy, or configuration; it does not prove that all PQC is unsupported.
Official references
Guidance reviewed 24 September 2026. Verify documentation for your deployed release; vendor capabilities and defaults change.