-
Bug
-
Resolution: Won't Fix
-
P3
-
None
-
15
-
None
-
b20
We get following warning while listing cacerts file entries. This will cause more questions to be raised for us to answer. For instance, "if cacerts have weaker keys then when will they be updated".
<thawtepremiumserverca [jdk]> uses a 1024-bit RSA key which is considered a security risk. This key size will be disabled in a future update
As far as I understand, disabling 1024 keys will not affect CA certificates. Should we have skipped cacerts keystore?
Not sure if we will disable other truststores from having weaker algorithms. if we won't disable then these warnings should be skipped for all truststores.
<thawtepremiumserverca [jdk]> uses a 1024-bit RSA key which is considered a security risk. This key size will be disabled in a future update
As far as I understand, disabling 1024 keys will not affect CA certificates. Should we have skipped cacerts keystore?
Not sure if we will disable other truststores from having weaker algorithms. if we won't disable then these warnings should be skipped for all truststores.
- relates to
-
JDK-8243559 Remove root certificates with 1024-bit keys
- Resolved
-
JDK-8255402 Warnings generated for JDK cacerts keystore
- Closed
-
JDK-8172404 Tools should warn if weak algorithms are used before restricting them
- Resolved