Uploaded image for project: 'JDK'
  1. JDK
  2. JDK-6938181

Timestamping validation should also check TSA certificate

XMLWordPrintable

    • Icon: Enhancement Enhancement
    • Resolution: Won't Fix
    • Icon: P3 P3
    • None
    • 6
    • deploy
    • generic
    • generic

      If revocation checking is disabled, then we should also allow the timestamp to be valid if the TSA certificate was valid when the timestamp was generated.

      However, if revocation checking is enabled, we need to also check if the TSA certificate was not revoked. This requires adding revocation information to the signed JAR (CRLs or OCSP Responses) when it is signed (see 6890876).

            herrick Andy Herrick (Inactive)
            mullan Sean Mullan
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:
              Resolved:
              Imported:
              Indexed: