RFR: 8285516: clearPassword should be called in a finally try block

Xue-Lei Andrew Fan xuelei at openjdk.java.net
Sun Apr 24 05:19:55 UTC 2022


Hi,

Could I have the simple update reviewed?

In the PKCS12 key store implementation, the PBEKeySpec.clearPassword() should be called in a finally try block.  Otherwise, the password cleanup could be interrupted by exceptions.

Thanks,
Xuelei

-------------

Commit messages:
 - 8285516: clearPassword should be called in a finally try block

Changes: https://git.openjdk.java.net/jdk/pull/8377/files
 Webrev: https://webrevs.openjdk.java.net/?repo=jdk&pr=8377&range=00
  Issue: https://bugs.openjdk.java.net/browse/JDK-8285516
  Stats: 7 lines in 1 file changed: 2 ins; 2 del; 3 mod
  Patch: https://git.openjdk.java.net/jdk/pull/8377.diff
  Fetch: git fetch https://git.openjdk.java.net/jdk pull/8377/head:pull/8377

PR: https://git.openjdk.java.net/jdk/pull/8377



More information about the security-dev mailing list