Uploaded image for project: 'JDK'
  1. JDK
  2. JDK-2191468

Jarsigner can't extract Extended Key Usage from Timestamp Reply currectly

XMLWordPrintable

    • b91
    • Verified

      PKCS #7 block includes a set of certificates and several signerinfos. To locate the certificate for a given signer, one should first look for a reference in the signerinfo, and then try to locate one in the certificates set.

      Currently, jarsigner, when validating certificate for a timestamping service, simply looks for a non-CA cert inside the certificate set. This is not correct.

            weijun Weijun Wang
            weijun Weijun Wang
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

              Created:
              Updated:
              Resolved:
              Imported:
              Indexed: