开发者

How to test the code signing of a JAR file on a client machine?

开发者 https://www.devze.com 2022-12-18 06:56 出处:网络
We have signed a JAR file using a certificate generated by MS Active Directory Certificate Services.However, when accessing it via Java Web Start we are getting the prompt that the digital signature c

We have signed a JAR file using a certificate generated by MS Active Directory Certificate Services. However, when accessing it via Java Web Start we are getting the prompt that the digital signature cannot be verified even though we've installed the root CA into the certificate store on the client machine.

Now trying to look at the root CA on the client machine, using "keytool -list", I'm seeing an exception (invalid URI:file://\my_msadcs_server\path\to\CRL.crl). So now I'm not sure exactly what is going wrong.

Anyone have a suggestion or sample Java code on how I can test the downloaded JAR file's signature on the client machine in an attempt to figure out exactly why JWS is complaining? It could be that the root CA certificate has a problem (and I will chase d开发者_Python百科own that avenue when my AD admin gets in) but I'd like to rule out other possibilities first. Currently the only thing I have to go on is the exception from "keytool -list", but keytool had no issues importing the root CA certificate in the first place.

Thanks in advance!,

mG.


I use jarsigner with the -verify, -verbose and -certs options. You may have to specify your -keystore, too.


I think the invalid URI message is a clue. Java file URI takes the following form: file://host/path

0

精彩评论

暂无评论...
验证码 换一张
取 消

关注公众号