Java Mailing List Archive

http://www.junlu.com/

Subjects
Home
mod jk2 https
Donation of JAXP 1 3 Sources to Apache
R annoyances
RE: Finding out when the aspnet admin worker process has recycled
Favorite Linux Distribution
eigenvalues of a circulant matrix
Apache Install
Reachin apache from outside
Ant should have an ext directory
Warning: Documentroot doesn 't exist
Can this be Done?
RE: Multilanguage Application
RE: Simple Question On setting up Sub Domain site
Lack of independence in anova()
How to close connection instead of sending 403?
winning the case for ANT
Re: adding php
New Ant GUI 'Ant 's Nest '
Narrowing Down A Strange Problem
Ant Task: sshexec
R Graph Gallery : categorization of the graphs
I 've been hacked, I need some help please
RE: Anyone working with DotNetNuke?
RE: Exception Handling Opinion
hex format
RE: IIS stopped working :(
<for > Build Failed:problem
RE: Separation of Objects from Logic
RE: Tracking pages with long request execution time
sending email to multiple destination
Web Site
ant UI
Easy cut & paste from Excel to R?
Win32 Apache Restart
Improving Tasks
HELP! PLEASE!
RE: Adding Controls to a Page
read table
RE: ASPNET account doesn 't exist!
Best way to uninstall Apache2 on red hat
from win to linux how to web page
XMLParseException changes and creation of XMLLocator2
Re Post: rewrite backslash to forward slash
Target or macrodef?
Page display problem XPSP2
Authentication problems
Dynamic Dictionary Data Type?
Newbie unable access my www from outside
off topic question: Latex and R in industries
Conflict between xtable and Hmisc when using Sweave?
Very old problem without any new solution
mod rewrite help
Basic Authentication question
RE: Code Security
calling ant from java program
prevent double signing
Re: Controlling Copy/Paste/Print
Using R to illustrate the Central Limit Theorem
web server slow too much slow
access to user directories
Links
Home
Official R Project Site
 
Search:  
Power your search with and, or, +, -, or "some phrase" operators.
prevent double signing

prevent double signing

2004-11-04       - By T E Schmitz
Reply:     <<     11     12     13     14     15     16     17  

Hello again,

Stefan Bodewig wrote:

> On Thu, 4 Nov 2004, Ivan Ivanov <rambiusparkisanius@(protected)> wrote:
>
> A signed jar contains the signature in a file named ALIAS.SF (ALIAS is
> a placeholder here) inside of the META-INF directory.  All the code in
> signjar does is checking for this file.
>
> It doesn not check whether the file contains anything useful or the
> signature is valid.

> Should have been in there for longer.  Let's see
> <http://cvs.apache.org/viewcvs.cgi/ant/src/main/org/apache/tools/ant/taskdefs
/SignJar.java?r1=1.7&r2=1.8>
> has been added for Ant 1.4.


I had a brief look at the source code of isSigned(). It looks to me as
though the method looks for a specific .SF file if alias is set (is this
the alias passed to the signjar task?).

 if (null == alias) {
<snip>
 } else {
 return jarFile.getEntry(SIG_START + alias.toUpperCase()
     + SIG_END) != null;

And why the hell toUpperCase()?
The jars signed by Sun contain a mixed case SF file (Sun_micr.sf). The
ones I signed with the signjar task produce a mixed case SF file, too.
In fact, in both cases the SF extension is *lowercase* while SIG_END is
uppercase.

Also, it looks to me as though isSigned() is always looking for
META-INF/<alias>.SF. Or is the alias not mandatory?

PS: this is not meant to be a criticism, but it would be good if the
documentation explained explicitly whether the lazy option checks if the
jar is signed with any signature or with the signature about to be added.

--


Regards/Gru?,

Tarlika


---------------------------------------------------------------------
To unsubscribe, e-mail: user-unsubscribe@(protected)
For additional commands, e-mail: user-help@(protected)


©2008 junlu.com - Jax Systems, LLC, U.S.A.