[jira] [Updated] (HTTPCLIENT-1265) Insecure certificate validation CVE-2012-5783

2012-12-16 Thread JIRA
[ https://issues.apache.org/jira/browse/HTTPCLIENT-1265?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Alberto Fernández updated HTTPCLIENT-1265: -- Summary: Insecure certificate validation CVE-2012-5783 (was: Insercure

[jira] [Closed] (HTTPCLIENT-1265) Insercure certificate validation CVE-2012-5783

2012-12-16 Thread JIRA
[ https://issues.apache.org/jira/browse/HTTPCLIENT-1265?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Alberto Fernández closed HTTPCLIENT-1265. - > Insercure certificate validation CVE-2012-5

[jira] [Commented] (HTTPCLIENT-1265) Insercure certificate validation CVE-2012-5783

2012-12-16 Thread JIRA
you very much. I've tested that the svn code compiles and passes the tests. I also have created a test case for this bug and attached it here. All necessary work is done, so I close the bug. > Insercure certificate validation C

[jira] [Updated] (HTTPCLIENT-1265) Insercure certificate validation CVE-2012-5783

2012-12-16 Thread JIRA
> Insercure certificate validation CVE-2012-5783 > -- > > Key: HTTPCLIENT-1265 > URL: https://issues.apache.org/jira/browse/HTTPCLIENT-1265 > Project: HttpComponents HttpClient >

[jira] [Resolved] (HTTPCLIENT-1265) Insercure certificate validation CVE-2012-5783

2012-12-16 Thread Oleg Kalnichevski (JIRA)
cursory review. I did not attempt to compile the source or run test cases. Oleg > Insercure certificate validation CVE-2012-5783 > -- > > Key: HTTPCLIENT-1265 > URL: https://issues.apache.

[jira] [Reopened] (HTTPCLIENT-1265) Insercure certificate validation CVE-2012-5783

2012-12-10 Thread JIRA
t 4.2, some bites from apache synapse and some refactor of my own (basically splitting in smaller functions). If you can also do a fast review to see if i've done a obvious mistake, i would very grateful. Thanks for your time and your patience > Insercure certificate v

[jira] [Updated] (HTTPCLIENT-1265) Insercure certificate validation CVE-2012-5783

2012-12-10 Thread JIRA
[ https://issues.apache.org/jira/browse/HTTPCLIENT-1265?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Alberto Fernández updated HTTPCLIENT-1265: -- Attachment: (was: CVE-2012-5783.patch) > Insercure certific

[jira] [Updated] (HTTPCLIENT-1265) Insercure certificate validation CVE-2012-5783

2012-12-10 Thread JIRA
[ https://issues.apache.org/jira/browse/HTTPCLIENT-1265?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Alberto Fernández updated HTTPCLIENT-1265: -- Attachment: CVE-2012-5783-2.patch > Insercure certificate validat

[jira] [Resolved] (HTTPCLIENT-1265) Insercure certificate validation CVE-2012-5783

2012-11-23 Thread Oleg Kalnichevski (JIRA)
[ https://issues.apache.org/jira/browse/HTTPCLIENT-1265?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Oleg Kalnichevski resolved HTTPCLIENT-1265. --- Resolution: Won't Fix > Insercure certificate validation

[jira] [Commented] (HTTPCLIENT-1265) Insercure certificate validation CVE-2012-5783

2012-11-23 Thread Oleg Kalnichevski (JIRA)
Oleg > Insercure certificate validation CVE-2012-5783 > -- > > Key: HTTPCLIENT-1265 > URL: https://issues.apache.org/jira/browse/HTTPCLIENT-1265 > Project: HttpComponents HttpClient >

[jira] [Updated] (HTTPCLIENT-1265) Insercure certificate validation CVE-2012-5783

2012-11-22 Thread JIRA
DNSSubjectAlts/CN matches the server name we are trying to connect to > Insercure certificate validation CVE-2012-5783 > -- > > Key: HTTPCLIENT-1265 > URL: https://issues.apache.org/jira/browse/

[jira] [Created] (HTTPCLIENT-1265) Insercure certificate validation CVE-2012-5783

2012-11-22 Thread JIRA
Alberto Fernández created HTTPCLIENT-1265: - Summary: Insercure certificate validation CVE-2012-5783 Key: HTTPCLIENT-1265 URL: https://issues.apache.org/jira/browse/HTTPCLIENT-1265 Project

Re: Certificate Validation

2008-12-09 Thread Oleg Kalnichevski
) ** thanks, Partha -Original Message- From: Oleg Kalnichevski [mailto:[EMAIL PROTECTED] Sent: Sunday, December 07, 2008 7:32 AM To: HttpComponents Project Subject: Re: Certificate Validation Partha

RE: Certificate Validation

2008-12-08 Thread Partha Venkatavaradhan (pavenkat)
) ** thanks, Partha -Original Message- From: Oleg Kalnichevski [mailto:[EMAIL PROTECTED] Sent: Sunday, December 07, 2008 7:32 AM To: HttpComponents Project Subject: Re: Certificate Validation Partha Venkatavaradhan (pavenkat) wrote: > Is

Re: Certificate Validation

2008-12-07 Thread Oleg Kalnichevski
e- From: Partha Venkatavaradhan (pavenkat) Sent: Wednesday, November 26, 2008 12:02 PM To: HttpComponents Project Subject: RE: Certificate Validation Hi, Looks like after I included the StrictSSLProtocolSocketFactory, now even a valid certificate like Thawte is declared as 'Peer not verfied

RE: Certificate Validation

2008-12-05 Thread Partha Venkatavaradhan (pavenkat)
x (IBM JRE), this call to registerProtocol results in 'Peer not verified' exception. Thanks in advance, Partha -Original Message- From: Partha Venkatavaradhan (pavenkat) Sent: Wednesday, November 26, 2008 12:02 PM To: HttpComponents Project Subject: RE: Certificate Validation H

RE: Certificate Validation

2008-11-26 Thread Partha Venkatavaradhan (pavenkat)
--Original Message- From: Ortwin Glück [mailto:[EMAIL PROTECTED] Sent: Tuesday, November 18, 2008 1:34 AM To: HttpComponents Project Subject: Re: Certificate Validation Hi Partha, Please have a look at http://hc.apache.org/httpclient-3.x/sslguide.html and especially then StrictSSLProtocolSocketFac

RE: Certificate Validation

2008-11-18 Thread Partha Venkatavaradhan (pavenkat)
Thanks Ortwin ! That worked Partha -Original Message- From: Ortwin Glück [mailto:[EMAIL PROTECTED] Sent: Tuesday, November 18, 2008 1:34 AM To: HttpComponents Project Subject: Re: Certificate Validation Hi Partha, Please have a look at http://hc.apache.org/httpclient-3.x

Re: Certificate Validation

2008-11-18 Thread Ortwin Glück
Hi Partha, Please have a look at http://hc.apache.org/httpclient-3.x/sslguide.html and especially then StrictSSLProtocolSocketFactory which is referenced there. Cheers, Ortwin Partha Venkatavaradhan (pavenkat) wrote: > Hi, > > > > I am running a tomcat server that has a valid certificate f

Certificate Validation

2008-11-18 Thread Partha Venkatavaradhan (pavenkat)
Hi, I am running a tomcat server that has a valid certificate from Thwate. In my HTTP client code I am letting the library handle the SSL validation and I am not using any custom trust validation. Now, everything works fine but the problem is precisely this. It works fine even when if I spec