Uploaded image for project: 'JDK'
  1. JDK
  2. JDK-6355119

Non-codeSigning certificates shouldn't be used for signing jars

XMLWordPrintable

    • b65
    • sparc
    • solaris_10

      A certificate has its special usages, which is marked by the KeyUsage, ExtendedKeyUsage or NetscapeCertType extensions inside it. When its usage is not specified for code signing (say, SSL server authentication), it shouldn't be used to sign a jar file. Therefore, jarsigner should print out a warning when such a certificate is used.

            weijun Weijun Wang
            weijun Weijun Wang
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

              Created:
              Updated:
              Resolved:
              Imported:
              Indexed: