Uploaded image for project: 'JDK'
  1. JDK
  2. JDK-4924896

Ship currently published CA certificates in cacerts file

XMLWordPrintable

    • 17
    • x86
    • windows_2000

        Name: gm110360 Date: 09/18/2003


        A DESCRIPTION OF THE REQUEST :
        The CA certificates provided in an installation of the J2SE runtime need to be refreshed with those currently used by Verisign, etc. For example, all but two of the Verisign CA certificates stored in a standard installation of the cacerts file are expired or due to expire in January of 2004. New versions of all of these expiring certificates are available and for the most part have been available for about seven years.

        JUSTIFICATION :
        Adding these certificates will make it so that a standard installation of J2SE can converse with SSL servers with recently signed certificates. Without these additions, applets and applications need to "patch" the cacerts file on every installation to assure that the CA certificates which are currently in use will be supported.


        CUSTOMER SUBMITTED WORKAROUND :
        A workaround is to "patch" the cacerts file with the CA certificate being used. Mind you, keytool does not have an end-user friendly interface.
        (Incident Review ID: 207526)
        ======================================================================

              hdongorcl Hao Dong (Inactive)
              gmanwanisunw Girish Manwani (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

                Created:
                Updated:
                Resolved:
                Imported:
                Indexed: