Uploaded image for project: 'JDK'
  1. JDK
  2. JDK-6279092

PKITS: two type of invalid certification path got "Unexpectedly accepted" since b39

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Duplicate
    • Icon: P3 P3
    • None
    • 6
    • security-libs
    • None

      The following two tests in the PKITS suite got "Unexpectedly accepted" after b39.

      Test 4.14.17 Invalid onlySomeReasons Test17
      # In this test, the intermediate certificate has issued two CRLs, one covering
      # the affiliationChanged and superseded reason codes and the other covering
      # the cessationOfOperation and certificateHold reason codes. The end entity
      # certificate is not listed on either CRL.
      # Procedure: Validate Invalid onlySomeReasons Test17 EE using the default
      # settings or open and verify Signed Test Message 6.2.2.182 using the default
      # settings.
      # Expected Result: The path should not validate successfully since the status
      # of the end entity certificate can not be determined.
      # Certification Path: The certification path is composed of the following
      # objects:
      # Trust Anchor Root Certificate, Trust Anchor Root CRL
      # onlySomeReasons CA2 Cert, onlySomeReasons CA2 CRL1, onlySomeReasons CA2 CRL2
      # Invalid onlySomeReasons Test17 EE
      Path InvalidonlySomeReasonsTest17EE.crt onlySomeReasonsCA2Cert.crt TrustAnchorRootCertificate.crt
      Result reject



      Test 4.15.4 Invalid delta-CRL Test4
      # In this test, the intermediate CA has issued a complete CRL and a delta-CRL.
      # The delta-CRL refers to the complete CRL as its base CRL. The end entity
      # certificate is listed as revoked on the delta-CRL.
      # Procedure: Validate Invalid deltaCRL Test4 EE using the default settings or
      # open and verify Signed Test Message 6.2.2.204 using the default settings.
      # Expected Result: The path should not validate successfully since the end
      # entity certificate has been revoked.
      # Certification Path: The certification path is composed of the following
      # objects:
      # Trust Anchor Root Certificate, Trust Anchor Root CRL
      # deltaCRL CA1 Cert, deltaCRL CA1 CRL, deltaCRL CA1 deltaCRL
      # Invalid deltaCRL Test4 EE
      Path InvaliddeltaCRLTest4EE.crt deltaCRLCA1Cert.crt TrustAnchorRootCertificate.crt
      Result reject
      ###@###.### 2005-06-01 21:15:55 GMT

            vinnie Vincent Ryan
            lzhanorcl Lichun Zhan (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

              Created:
              Updated:
              Resolved:
              Imported:
              Indexed: