[9] RFR 8163503: PKCS12 keystore cannot store non-X.509 certificates

Vincent Ryan vincent.x.ryan at oracle.com
Tue Aug 9 18:14:14 UTC 2016


Please review this fix to improve the error handling for attempts to store a Certificate object in PKCS12 keystore.
The PKCS12 keystore implementation supports storing only X509Certificate objects but the KeyStore API allows Certificate objects.
This fix rejects attempts to store non-X.509 certificates and throws a KeyStoreException.

Thanks.

Bug: https://bugs.openjdk.java.net/browse/JDK-8163503
Webrev: http://cr.openjdk.java.net/~vinnie/8163503/webrev.00/





More information about the security-dev mailing list