-
Bug
-
Resolution: Fixed
-
P3
-
8, 11, 18
-
b03
Issue | Fix Version | Assignee | Priority | Status | Resolution | Resolved In Build |
---|---|---|---|---|---|---|
JDK-8270582 | 17.0.1 | Rajan Halade | P3 | Resolved | Fixed | b03 |
JDK-8269000 | 17 | Rajan Halade | P3 | Resolved | Fixed | b28 |
JDK-8269002 | 11.0.13-oracle | Rajan Halade | P3 | Resolved | Fixed | b01 |
JDK-8269291 | 11.0.12 | Rajan Halade | P3 | Resolved | Fixed | b06 |
JDK-8321212 | openjdk8u412 | Andrew Hughes | P3 | Resolved | Fixed | b01 |
JDK-8269173 | 8u311 | Rajan Halade | P3 | Resolved | Fixed | b01 |
JDK-8269174 | 7u321 | Rajan Halade | P3 | Resolved | Fixed | b01 |
==================================
certpath: OCSP response validity interval is from Tue Jun 09 22:00:00 UTC 2020 until Wed Jun 09 00:00:00 UTC 2021
certpath: Checking validity of OCSP response on Mon Jun 14 12:58:58 UTC 2021 with allowed interval between Mon Jun 14 12:43:58 UTC 2021 and Mon Jun 14 13:13:58 UTC 2021
certpath: X509CertSelector.match(SN: 9b7e0649a33e62b9d5ee90487129ef57
Issuer: CN=VeriSign Class 3 Public Primary Certification Authority - G3, OU="(c) 1999 VeriSign, Inc. - For authorized use only", OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US
Subject: CN=VeriSign Class 3 Public Primary Certification Authority - G3, OU="(c) 1999 VeriSign, Inc. - For authorized use only", OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US)
certpath: X509CertSelector.match: subject DNs don't match
certpath: X509CertSelector.match(SN: 10020
Issuer: CN=Certum CA, O=Unizeto Sp. z o.o., C=PL
Subject: CN=Certum CA, O=Unizeto Sp. z o.o., C=PL)
certpath: X509CertSelector.match: subject DNs don't match
java.lang.RuntimeException: TEST FAILED: couldn't determine EE certificate status
at ValidatePathWithParams.validate(ValidatePathWithParams.java:177)
at LetsEncryptCA.main(LetsEncryptCA.java:172)
at java.base/jdk.internal.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
at java.base/jdk.internal.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:77)
at java.base/jdk.internal.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
at java.base/java.lang.reflect.Method.invoke(Method.java:568)
at com.sun.javatest.regtest.agent.MainWrapper$MainThread.run(MainWrapper.java:127)
at java.base/java.lang.Thread.run(Thread.java:833)
Caused by: java.security.cert.CertPathValidatorException: Response is unreliable: its validity interval is out-of-date
at java.base/sun.security.provider.certpath.PKIXMasterCertPathValidator.validate(PKIXMasterCertPathValidator.java:135)
at java.base/sun.security.provider.certpath.PKIXCertPathValidator.validate(PKIXCertPathValidator.java:224)
at java.base/sun.security.provider.certpath.PKIXCertPathValidator.validate(PKIXCertPathValidator.java:144)
at java.base/sun.security.provider.certpath.PKIXCertPathValidator.engineValidate(PKIXCertPathValidator.java:83)
at java.base/java.security.cert.CertPathValidator.validate(CertPathValidator.java:309)
at ValidatePathWithParams.doCertPathValidate(ValidatePathWithParams.java:288)
at ValidatePathWithParams.validate(ValidatePathWithParams.java:142)
... 7 more
Caused by: java.security.cert.CertPathValidatorException: Response is unreliable: its validity interval is out-of-date
at java.base/sun.security.provider.certpath.OCSPResponse.verify(OCSPResponse.java:617)
at java.base/sun.security.provider.certpath.OCSP.check(OCSP.java:199)
at java.base/sun.security.provider.certpath.RevocationChecker.checkOCSP(RevocationChecker.java:785)
at java.base/sun.security.provider.certpath.RevocationChecker.check(RevocationChecker.java:369)
at java.base/sun.security.provider.certpath.RevocationChecker.check(RevocationChecker.java:343)
at java.base/sun.security.provider.certpath.PKIXMasterCertPathValidator.validate(PKIXMasterCertPathValidator.java:125)
... 13 more
JavaTest Message: Test threw exception: java.lang.RuntimeException: TEST FAILED: couldn't determine EE certificate status
JavaTest Message: shutting down test
STATUS:Failed.`main' threw exception: java.lang.RuntimeException: TEST FAILED: couldn't determine EE certificate status
==================================
- backported by
-
JDK-8269000 LetsEncryptCA.java test fails as Let’s Encrypt Authority X3 is retired
- Resolved
-
JDK-8269002 LetsEncryptCA.java test fails as Let’s Encrypt Authority X3 is retired
- Resolved
-
JDK-8269173 LetsEncryptCA.java test fails as Let’s Encrypt Authority X3 is retired
- Resolved
-
JDK-8269174 LetsEncryptCA.java test fails as Let’s Encrypt Authority X3 is retired
- Resolved
-
JDK-8269291 LetsEncryptCA.java test fails as Let’s Encrypt Authority X3 is retired
- Resolved
-
JDK-8270582 LetsEncryptCA.java test fails as Let’s Encrypt Authority X3 is retired
- Resolved
-
JDK-8321212 LetsEncryptCA.java test fails as Let’s Encrypt Authority X3 is retired
- Resolved
- relates to
-
JDK-8270280 security/infra/java/security/cert/CertPathValidator/certification/LetsEncryptCA.java OCSP response error
- Resolved
- links to
-
Commit openjdk/jdk8u-dev/b610be3d
-
Commit openjdk/jdk17/483f1ee2
-
Commit openjdk/jdk/58e6e6d9
-
Review openjdk/jdk8u-dev/390
-
Review openjdk/jdk11u-dev/56
-
Review openjdk/jdk17/94
-
Review openjdk/jdk/4524