Release Note: Add mechanism to allow non default root CAs to not be subject to algorithm restrictions

XMLWordPrintable

    • Verified

        '**New certpath constraint: jdkCA**
        In the `java.security` file, an additional constraint named "jdkCA" is added to the `jdk.certpath.disabledAlgorithms` property. This constraint prohibits the specified algorithm only if the algorithm is used in a certificate chain that terminates at a marked trust anchor in the lib/security/cacerts keystore. If the jdkCA constraint is not set, then all chains using the specified algorithm are restricted. jdkCA may only be used once in a DisabledAlgorithm expression.

        Example:  To apply this constraint to SHA-1 certificates, include
        the following:  ```SHA1 jdkCA```

              Assignee:
              Anthony Scarpino
              Reporter:
              Anthony Scarpino
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: