Java Plugin 1.4 with JRE 1.3 -> Ignores certificates.

From: Daniel Kasmeroglu (daniel.kasmeroglu@web.de)
Date: 08/25/01


Date: 24 Aug 2001 22:58:58 -0000
Message-ID: <20010824225858.19674.qmail@securityfocus.com>
From: Daniel Kasmeroglu <daniel.kasmeroglu@web.de>
To: bugtraq@securityfocus.com
Subject: Java Plugin 1.4 with JRE 1.3 -> Ignores certificates.

During work I've found out that the combination of the
Java Plugin 1.4 with the JRE 1.3 doesn't handle
certificates properly. An applet signed with an
outdated certificate shouldn't be able to get access to
the filesystem on the client machine. However this
happens when using the named combination. So my
applet was able to do some filesystem operations
without a valid certificate. For better bugtracking I've
generated some files (HTML,JSP,Applet,Certificate)
to reproduce this problem.

Here you'll find these files:
  http://user.cs.tu-berlin.de/~raptor/SecurityFault/

Starting point is the file SecurityFault.html .If you got
JBuilder a corresponding project file is included.



Relevant Pages

  • SUN JRE 1.5.0_06 client certificate selection problem on SSL client authentication
    ... JRE 1.5.0_06 if a SSL client authentication has to be done. ... signature and has only the key usage "Digital Signature" set. ... A java applet should now establish a SSL connection to the server. ... certificates has the needed key usage "Digital Signature" set. ...
    (comp.lang.java.security)
  • Upgrading certificates
    ... I need to upgrade the store of certificates of a JDK1.3.10, ... JRE 1.6 has no problem with the sites. ... files such as the CACERTS file simply be copied from the more recent ... or should some other method be followed to upgrade ...
    (comp.lang.java.security)