Uploaded image for project: 'JDK'
  1. JDK
  2. JDK-4431684

jar signature certificate key usage check incorrect

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Fixed
    • Icon: P4 P4
    • 6
    • 1.3.0
    • security-libs
    • None
    • beta
    • generic
    • generic

      When verifying the signature of a jar file we check the signer
      certificate KeyUsage extension and require that the digitalSignature
      bit is set. This is incorrect as RFC2459 says we should recognize
      digitalSignature and/or the non-repudiation bit.

            weijun Weijun Wang
            jdn Jeffrey Nisewanger (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

              Created:
              Updated:
              Resolved:
              Imported:
              Indexed: