Uploaded image for project: 'JDK'
  1. JDK
  2. JDK-4776794

Backout CertPath EKU check in CA certificates

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Fixed
    • Icon: P4 P4
    • 1.4.2
    • 1.4.2
    • security-libs
    • mantis
    • generic
    • generic
    • Verified

      With 4636027 we introduced an extended key usage check in CA certificates. If they contain the EKU extension, they are only allowed if they include the anyExtendedKeyUsage value. This was in response to changes in PKIX RFC3280.

      It turns out that this is an incorrect interpretation of RFC3280, which is somewhat unclear in this respect. One of the authors (Russ Housley) clarified that the EKU extension should be ignored in CA certificates.

            andreas Andreas Sterbenz
            andreas Andreas Sterbenz
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

              Created:
              Updated:
              Resolved:
              Imported:
              Indexed: