RMI secure transport provider uses mutable public credentials

XMLWordPrintable

    • Type: Bug
    • Resolution: Won't Fix
    • Priority: P4
    • None
    • Affects Version/s: 1.4.0
    • Component/s: core-libs
    • generic
    • generic

      The JSSE-based secure RMI transport provider expects public
      credentials that are a java.security.cert.Certificate array
      representing the associated certificate chain. Because arrays are
      mutable, this arrangement allows applications with access to the
      subject, and no additional permissions, to modify the public
      credentials of the subject, even if the subject is read-only.

            Assignee:
            J. Duke
            Reporter:
            J. Duke
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

              Created:
              Updated:
              Resolved:
              Imported:
              Indexed: