-
Bug
-
Resolution: Fixed
-
P4
-
7u40, 8
-
7u40 b43,7u40 b40, win x86,FF14
-
b01
Issue | Fix Version | Assignee | Priority | Status | Resolution | Resolved In Build |
---|---|---|---|---|---|---|
JDK-8068814 | 9 | Andy Herrick | P4 | Resolved | Fixed | b52 |
JDK-8082212 | emb-9 | Andy Herrick | P4 | Resolved | Fixed | b52 |
JDK-8086313 | 8u65 | Andy Herrick | P4 | Resolved | Fixed | b01 |
JDK-8137465 | emb-8u65 | Unassigned | P4 | Resolved | Fixed | b01 |
JDK-8076793 | emb-8u60 | Andy Herrick | P4 | Resolved | Fixed | team |
This might be a regression.
When the rule set file is signed with cert containing OCSP information, and it cannot connect to the OCSP server, it should still work as valid. Now it works as a wrong rule set file and block the applet.
Steps to reproduce:
1.Dowload http://sqeweb.us.oracle.com/deployment2/sheldon/webCases/PolicyFileValidation/policy_template/policy_publicRevoked.jar and install it.
2.Disconnect from internet by unsetting proxy.
3.Launch the applet from http://sqeweb.us.oracle.com/deployment2/sheldon/webCases/PolicyFileValidation/html/hello_appletTag.html
4.If it is blocked with "Cannot Verify RuleSet", bug is reproducible. It should get launched.
Also if the OCSP server is accessible, and the cert is revoked. it should come out with dialog "Certificate has been revoked". Now it is "Cannot Verify RuleSet".
Attachment are the trace for OCSP server accessible and inaccessible scenarios.
When the rule set file is signed with cert containing OCSP information, and it cannot connect to the OCSP server, it should still work as valid. Now it works as a wrong rule set file and block the applet.
Steps to reproduce:
1.Dowload http://sqeweb.us.oracle.com/deployment2/sheldon/webCases/PolicyFileValidation/policy_template/policy_publicRevoked.jar and install it.
2.Disconnect from internet by unsetting proxy.
3.Launch the applet from http://sqeweb.us.oracle.com/deployment2/sheldon/webCases/PolicyFileValidation/html/hello_appletTag.html
4.If it is blocked with "Cannot Verify RuleSet", bug is reproducible. It should get launched.
Also if the OCSP server is accessible, and the cert is revoked. it should come out with dialog "Certificate has been revoked". Now it is "Cannot Verify RuleSet".
Attachment are the trace for OCSP server accessible and inaccessible scenarios.
- backported by
-
JDK-8068814 DRS: The messaging for invalid rule set jar is not explicit.
-
- Resolved
-
-
JDK-8076793 DRS: The messaging for invalid rule set jar is not explicit.
-
- Resolved
-
-
JDK-8082212 DRS: The messaging for invalid rule set jar is not explicit.
-
- Resolved
-
-
JDK-8086313 DRS: The messaging for invalid rule set jar is not explicit.
-
- Resolved
-
-
JDK-8137465 DRS: The messaging for invalid rule set jar is not explicit.
-
- Resolved
-