Non-codeSigning certificates shouldn't be used for signing jars

XMLWordPrintable

    • b65
    • sparc
    • solaris_10

      A certificate has its special usages, which is marked by the KeyUsage, ExtendedKeyUsage or NetscapeCertType extensions inside it. When its usage is not specified for code signing (say, SSL server authentication), it shouldn't be used to sign a jar file. Therefore, jarsigner should print out a warning when such a certificate is used.

            Assignee:
            Weijun Wang
            Reporter:
            Weijun Wang
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

              Created:
              Updated:
              Resolved:
              Imported:
              Indexed: