[security-dev 00686]: hg: jdk7/tl/jdk: 6798714: OCSPResponse class has to check the validity of signing certificate for OCSP response

xuelei.fan at sun.com xuelei.fan at sun.com
Fri Mar 13 05:20:06 UTC 2009


Changeset: f381e737916d
Author:    xuelei
Date:      2009-03-13 12:59 +0800
URL:       http://hg.openjdk.java.net/jdk7/tl/jdk/rev/f381e737916d

6798714: OCSPResponse class has to check the validity of signing certificate for OCSP response
Summary: checking validity and ocsp-nocheck extension.
Reviewed-by: mullan, vinnie

! src/share/classes/sun/security/provider/certpath/OCSPResponse.java
+ src/share/classes/sun/security/x509/OCSPNoCheckExtension.java
! src/share/classes/sun/security/x509/OIDMap.java
! src/share/classes/sun/security/x509/PKIXExtensions.java




More information about the security-dev mailing list