Uploaded image for project: 'Geronimo'
  1. Geronimo
  2. GERONIMO-2443

Import CA reply should match the public key in the keystore with that in the certificate from CA.

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Major
    • Resolution: Fixed
    • 1.1.1, 1.2
    • 1.1.2, 1.2
    • security
    • Security Level: public (Regular issues)
    • None
    • G1.1.1

    • Patch Available

    Description

      While importing CA reply into the keystore, the public key in the certificate issued by the CA should be matched with the public key that is currently in the keystore. java.securtiy.KeyStore.setKeyEntry does not complain if the privateKey and the publicKey in the certificate are not related An accidental import of a certificate corresponding to one public key along with an unrelated private key renders the key pair useless and results in errors while using the certificate.

      Attachments

        1. GERONIMO-2443-v1.2.patch
          1 kB
          Vamsavardhana Reddy

        Activity

          People

            Unassigned Unassigned
            vamsic Vamsavardhana Reddy
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: