Uploaded image for project: 'JDK'
  1. JDK
  2. JDK-4407861

RMI secure transport provider uses mutable public credentials

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Won't Fix
    • Icon: P4 P4
    • None
    • 1.4.0
    • core-libs
    • generic
    • generic

      The JSSE-based secure RMI transport provider expects public
      credentials that are a java.security.cert.Certificate array
      representing the associated certificate chain. Because arrays are
      mutable, this arrangement allows applications with access to the
      subject, and no additional permissions, to modify the public
      credentials of the subject, even if the subject is read-only.

            duke J. Duke
            duke J. Duke
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

              Created:
              Updated:
              Resolved:
              Imported:
              Indexed: