RFR: 8285516: clearPassword should be called in a finally try block
    Xue-Lei Andrew Fan 
    xuelei at openjdk.java.net
       
    Sun Apr 24 05:19:55 UTC 2022
    
    
  
Hi,
Could I have the simple update reviewed?
In the PKCS12 key store implementation, the PBEKeySpec.clearPassword() should be called in a finally try block.  Otherwise, the password cleanup could be interrupted by exceptions.
Thanks,
Xuelei
-------------
Commit messages:
 - 8285516: clearPassword should be called in a finally try block
Changes: https://git.openjdk.java.net/jdk/pull/8377/files
 Webrev: https://webrevs.openjdk.java.net/?repo=jdk&pr=8377&range=00
  Issue: https://bugs.openjdk.java.net/browse/JDK-8285516
  Stats: 7 lines in 1 file changed: 2 ins; 2 del; 3 mod
  Patch: https://git.openjdk.java.net/jdk/pull/8377.diff
  Fetch: git fetch https://git.openjdk.java.net/jdk pull/8377/head:pull/8377
PR: https://git.openjdk.java.net/jdk/pull/8377
    
    
More information about the security-dev
mailing list