Uploaded image for project: 'JDK'
  1. JDK
  2. JDK-6381630

New certificate warning with 5.0U6 flags certs as invalid instead of untrusted

    XMLWordPrintable

Details

    • Bug
    • Resolution: Fixed
    • P3
    • 5.0u7
    • 5.0u6
    • deploy
    • b02
    • generic
    • generic

    Backports

      Description

        The new security enhancement done for JVM 5.0U6 regarding the change in the warning message for certificates is causing concern and issues for customers.

        This new message now states that if a certificate is untrusted it is now flagged as invalid. This wording is causing problems for customers using self signed certificates as the cert is not technically invalid but rather untrusted. This was changed in update 6.

        The customer is requesting that this be changed. They do not disagree that the warning should be scarier or that we are making security enhancements, but they would rather the wording reflect the true nature of why it is being flagged and not a blanket "invalid" certificate message.
        The customer is complain about text in our security dialog box for untrusted server certificate, which we state:
        "The web site's certificate is invalid. Do you want to continue?"

        We are going to change to:
        "The web site's certificate cannot be verified. Do you want to continue?"

        Attachments

          Issue Links

            Activity

              People

                dgu Dennis Gu (Inactive)
                msusko Mark Susko (Inactive)
                Votes:
                0 Vote for this issue
                Watchers:
                1 Start watching this issue

                Dates

                  Created:
                  Updated:
                  Resolved:
                  Imported:
                  Indexed: