Java TLS: how to disable certain handshake features
15:28 15 Dec 2025

When looking at PCAP traces of Java TLS handshake, I can see details in Client Hello like this:

Signature Algorithm: SHA224 DSA (0x0302)

I would like to disable it, so server application does not offer it to the client. As far as I understand, this can be done in JAVA_HOME/conf/java.security

There is already an entry like this:

jdk.tls.disabledAlgorithms=SSLv3, TLSv1, TLSv1.1, DTLSv1.0, RC4, DES, \
    MD5withRSA, DH keySize < 1024, EC keySize < 224, 3DES_EDE_CBC, anon, NULL, \
    ECDH, TLS_RSA_*, rsa_pkcs1_sha1 usage HandshakeSignature, \
    ecdsa_sha1 usage HandshakeSignature, dsa_sha1 usage HandshakeSignature

Is this the right place and what is needed to be entered here, to achive this?

java ssl ssl-handshake