-
Enhancement
-
Resolution: Fixed
-
P3
-
7, 26
-
b09
Issue | Fix Version | Assignee | Priority | Status | Resolution | Resolved In Build |
---|---|---|---|---|---|---|
JDK-8364457 | 25.0.2 | Rajan Halade | P3 | Resolved | Fixed | master |
JDK-8364371 | 21.0.10-oracle | Rajan Halade | P3 | Resolved | Fixed | master |
JDK-8364458 | 17.0.18-oracle | Rajan Halade | P3 | Resolved | Fixed | master |
JDK-8364460 | 11.0.30-oracle | Rajan Halade | P3 | Resolved | Fixed | master |
JDK-8364459 | 8u481 | Rajan Halade | P3 | Resolved | Fixed | master |
JDK-8364462 | 7u491 | Rajan Halade | P3 | Resolved | Fixed | master |
"The CAs not being transferred comprise of roots and CAs that were never used by subscribers, and also the roots and CAs for 'Affirmtrust'."
Even though we are already distrusting the AffirmTrust roots by default, we should now take the next step and remove them from the JDK, as they are no longer active and revocation services and other important infrastructure won't be maintained.
We include 4 AffirmTrust roots in the JDK.
- backported by
-
JDK-8364371 Remove AffirmTrust root CAs
-
- Resolved
-
-
JDK-8364457 Remove AffirmTrust root CAs
-
- Resolved
-
-
JDK-8364458 Remove AffirmTrust root CAs
-
- Resolved
-
-
JDK-8364459 Remove AffirmTrust root CAs
-
- Resolved
-
-
JDK-8364460 Remove AffirmTrust root CAs
-
- Resolved
-
-
JDK-8364462 Remove AffirmTrust root CAs
-
- Resolved
-
- relates to
-
JDK-8337664 Distrust TLS server certificates issued after Oct 2024 and anchored by Entrust Root CAs
-
- Resolved
-
- links to
-
Commit(master) openjdk/jdk25u/e58859e8
-
Commit(master) openjdk/jdk/3bdac531
-
Review(master) openjdk/jdk25u/53
-
Review(master) openjdk/jdk/26538