Uploaded image for project: 'JDK'
  1. JDK
  2. JDK-8314180 Disable XPath in XML Signatures
  3. JDK-8359342

Release Note: Disable XPath in XML Signatures

XMLWordPrintable

    • Icon: Sub-task Sub-task
    • Resolution: Delivered
    • Icon: P4 P4
    • 26
    • None
    • security-libs

      XML signatures that use XPath transforms have been disabled by default. The XPath transform is not recommended by the [XML Signature Best Practices](https://www.w3.org/TR/xmldsig-bestpractices/) document. Applications should use the XPath Filter 2.0 transform instead, which was designed to be an alternative to the XPath transform. If necessary, and at their own risk, applications can workaround this policy by modifying the `jdk.xml.dsig.secureValidationPolicy` security property and re-enabling the XPath transform.

            mullan Sean Mullan
            mullan Sean Mullan
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:
              Resolved: