Uploaded image for project: 'JDK'
  1. JDK
  2. JDK-5066142

javax.net.ssl.* keyStore, password properties - specify securely/privately

    XMLWordPrintable

Details

    • Fix Understood
    • generic
    • generic

    Description

      HttpsURLConnection uses javax.net.ssl.keyStore and keyStorePassword system properties for access to a user's keystore. Currently these properties are settable as system properties on the Java VM startup command line via -Djavax.net.ssl.keyStore=..., etc. This default keyStore access mechanism should be more securely and privately handled.

      Users and ISVs relying upon Java's HttpsURLConnection have expressed security concerns with the VM system property machinery currently used, its visibility on running systems, in scripts, etc., and request a more secure and private keystore access mechanism.

      Attachments

        Activity

          People

            wetmore Bradford Wetmore
            duke J. Duke
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Imported:
              Indexed: