[security-dev 00686]: hg: jdk7/tl/jdk: 6798714: OCSPResponse class has to check the validity of signing certificate for OCSP response
xuelei.fan at sun.com
xuelei.fan at sun.com
Fri Mar 13 05:20:06 UTC 2009
Changeset: f381e737916d
Author: xuelei
Date: 2009-03-13 12:59 +0800
URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/f381e737916d
6798714: OCSPResponse class has to check the validity of signing certificate for OCSP response
Summary: checking validity and ocsp-nocheck extension.
Reviewed-by: mullan, vinnie
! src/share/classes/sun/security/provider/certpath/OCSPResponse.java
+ src/share/classes/sun/security/x509/OCSPNoCheckExtension.java
! src/share/classes/sun/security/x509/OIDMap.java
! src/share/classes/sun/security/x509/PKIXExtensions.java
More information about the security-dev
mailing list