Uploaded image for project: 'JDK'
  1. JDK
  2. JDK-4531295

should enforce the signer restraint on policy files

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Fixed
    • Icon: P4 P4
    • 1.4.1
    • 1.4.0
    • security-libs
    • None
    • hopper
    • generic
    • generic
    • Verified

        Per JCE documentation, the two jurisdiction policy files need to be signed by the same signer as the JCE framework jar file.
        Currently, signature check is performed as well as trust chain validation.
        However, we should add an additional check which makes sure the signer of the 3 jars, i.e. two jurisdiction policy files and JCE framework file, is the same.

              valeriep Valerie Peng
              valeriep Valerie Peng
              Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

                Created:
                Updated:
                Resolved:
                Imported:
                Indexed: