Uploaded image for project: 'JDK'
  1. JDK
  2. JDK-4407856

RMI secure transport provider doesn't timeout SSL sessions

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Won't Fix
    • Icon: P4 P4
    • None
    • 1.4.0
    • core-libs
    • generic
    • generic

      The JSSE-based secure RMI transport provider continues to use SSL
      sessions for an arbitrary length of time. Common practice suggests
      that it should not use sessions for more than 24 hours.

      In addition, the provider needs to handle sessions being invalidated
      asynchronously by the server to permit it working with server
      endpoints where SSL encryption and decryption are handled by a
      firewall or servlet.

            duke J. Duke
            duke J. Duke
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

              Created:
              Updated:
              Resolved:
              Imported:
              Indexed: