Uploaded image for project: 'JDK'
  1. JDK
  2. JDK-4319996

Must check certificate validity when verifying signatures on providers

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Fixed
    • Icon: P2 P2
    • 1.2.1
    • 1.2.1
    • security-libs
    • None
    • 1.2.1beta
    • generic
    • solaris_7

      We plan to give certificates w/ short validity for testing only.

      So we must check certificate validity when verifying signatures on providers.
      If not, one could just sign his provider w/ a testing certificate and
      use his provider all the time.

      Also, we should check BasicConstrain extension if it is marked "critical".

            shihliu Sharon Liu (Inactive)
            shihliu Sharon Liu (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

              Created:
              Updated:
              Resolved:
              Imported:
              Indexed: