-
Bug
-
Resolution: Fixed
-
P3
-
None
-
b13
-
Verified
Currently, the jarsigner tool does not warn you if algorithms used in signature/digest parameters are using legacy or disabled algorithms. For example, the parameters for the RSASSA-PSS signature algorithm contain two fields (hashAlgorithm and maskGenAlgorithm) that should be checked against the algorithm constraint properties.
These algorithms however, are properly restricted at runtime, and if disabled, the JAR is treated as unsigned.
These algorithms however, are properly restricted at runtime, and if disabled, the JAR is treated as unsigned.
- relates to
-
JDK-8283665 Two Jarsigner tests needs to be updated with JDK-8267319
- Resolved
-
JDK-8275887 jarsigner prints invalid digest/signature algorithm warnings if keysize is weak/disabled
- Resolved