Friday, September 23, 2011

Oracle makes free Java binaries safer - and inoperable

Oracle makes free Java binaries safer - and inoperable

Users have been complaining recently about the fact that Java 3D
applications (as an applet) as well as Java Web Start applications are
not allowed to run with a reference to an unsigned jar files. From a
forum message by Kevin Rushforth, Principal Member of Technical Staff at
Oracle, now go forth first clues. Sun Java binaries were previously
provided by Sun with a certificate. Oracle is now, however, came to the
conclusion that it could pose a security risk, this outdated binaries
with Sun-reward certificates - the certificates and have therefore
removed for binaries among download.java.net. Accordingly, let
applications that query these certificates are no longer running.

Want the benefit of using the Java 3D apps as an applet or Java Web
Start application still must sign their own files, now first. Rushforth
recommends to the following four steps:

Download the files

java3d-1.5.2.jnlp
vecmath.jar
and all Java 3D jars from the directory
download.java.net/media/java3d/webstart/release/j3d/1.5.2 /

Sign all jar files with its own certificate (or via self-signing).
All JNLP and jar files saved with the application.
The JNLP file to add the correct path name.

Oracle's decision to surrender the old certificates not met already on
the first criticism. Among other things, the company is accused of
failing to timely inform the user. Actually found on the project site is
currently no evidence of the missing certificates.

No comments:

Post a Comment