[
https://issues.apache.org/jira/browse/HTTPCLIENT-1265?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Alberto Fernández updated HTTPCLIENT-1265:
--
Summary: Insecure certificate validation CVE-2012-5783 (was: Insercure
[
https://issues.apache.org/jira/browse/HTTPCLIENT-1265?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Alberto Fernández closed HTTPCLIENT-1265.
-
> Insercure certificate validation CVE-2012-5
you very much.
I've tested that the svn code compiles and passes the tests. I also have
created a test case for this bug and attached it here.
All necessary work is done, so I close the bug.
> Insercure certificate validation C
> Insercure certificate validation CVE-2012-5783
> --
>
> Key: HTTPCLIENT-1265
> URL: https://issues.apache.org/jira/browse/HTTPCLIENT-1265
> Project: HttpComponents HttpClient
>
cursory review. I did not attempt to
compile the source or run test cases.
Oleg
> Insercure certificate validation CVE-2012-5783
> --
>
> Key: HTTPCLIENT-1265
> URL: https://issues.apache.
t 4.2, some bites from apache
synapse and some refactor of my own (basically splitting in smaller functions).
If you can also do a fast review to see if i've done a obvious mistake, i would
very grateful.
Thanks for your time and your patience
> Insercure certificate v
[
https://issues.apache.org/jira/browse/HTTPCLIENT-1265?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Alberto Fernández updated HTTPCLIENT-1265:
--
Attachment: (was: CVE-2012-5783.patch)
> Insercure certific
[
https://issues.apache.org/jira/browse/HTTPCLIENT-1265?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Alberto Fernández updated HTTPCLIENT-1265:
--
Attachment: CVE-2012-5783-2.patch
> Insercure certificate validat
[
https://issues.apache.org/jira/browse/HTTPCLIENT-1265?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Oleg Kalnichevski resolved HTTPCLIENT-1265.
---
Resolution: Won't Fix
> Insercure certificate validation
Oleg
> Insercure certificate validation CVE-2012-5783
> --
>
> Key: HTTPCLIENT-1265
> URL: https://issues.apache.org/jira/browse/HTTPCLIENT-1265
> Project: HttpComponents HttpClient
>
DNSSubjectAlts/CN matches the server name we
are trying to connect to
> Insercure certificate validation CVE-2012-5783
> --
>
> Key: HTTPCLIENT-1265
> URL: https://issues.apache.org/jira/browse/
Alberto Fernández created HTTPCLIENT-1265:
-
Summary: Insercure certificate validation CVE-2012-5783
Key: HTTPCLIENT-1265
URL: https://issues.apache.org/jira/browse/HTTPCLIENT-1265
Project
)
**
thanks,
Partha
-Original Message-
From: Oleg Kalnichevski [mailto:[EMAIL PROTECTED]
Sent: Sunday, December 07, 2008 7:32 AM
To: HttpComponents Project
Subject: Re: Certificate Validation
Partha
)
**
thanks,
Partha
-Original Message-
From: Oleg Kalnichevski [mailto:[EMAIL PROTECTED]
Sent: Sunday, December 07, 2008 7:32 AM
To: HttpComponents Project
Subject: Re: Certificate Validation
Partha Venkatavaradhan (pavenkat) wrote:
> Is
e-
From: Partha Venkatavaradhan (pavenkat)
Sent: Wednesday, November 26, 2008 12:02 PM
To: HttpComponents Project
Subject: RE: Certificate Validation
Hi,
Looks like after I included the StrictSSLProtocolSocketFactory, now even a
valid certificate like Thawte is declared as 'Peer not verfied
x (IBM JRE), this call to registerProtocol results in
'Peer not verified' exception.
Thanks in advance,
Partha
-Original Message-
From: Partha Venkatavaradhan (pavenkat)
Sent: Wednesday, November 26, 2008 12:02 PM
To: HttpComponents Project
Subject: RE: Certificate Validation
H
--Original Message-
From: Ortwin Glück [mailto:[EMAIL PROTECTED]
Sent: Tuesday, November 18, 2008 1:34 AM
To: HttpComponents Project
Subject: Re: Certificate Validation
Hi Partha,
Please have a look at
http://hc.apache.org/httpclient-3.x/sslguide.html
and especially then
StrictSSLProtocolSocketFac
Thanks Ortwin !
That worked
Partha
-Original Message-
From: Ortwin Glück [mailto:[EMAIL PROTECTED]
Sent: Tuesday, November 18, 2008 1:34 AM
To: HttpComponents Project
Subject: Re: Certificate Validation
Hi Partha,
Please have a look at
http://hc.apache.org/httpclient-3.x
Hi Partha,
Please have a look at
http://hc.apache.org/httpclient-3.x/sslguide.html
and especially then
StrictSSLProtocolSocketFactory which is referenced there.
Cheers,
Ortwin
Partha Venkatavaradhan (pavenkat) wrote:
> Hi,
>
>
>
> I am running a tomcat server that has a valid certificate f
Hi,
I am running a tomcat server that has a valid certificate from Thwate.
In my HTTP client code I am letting the library handle the SSL
validation and I am not using any custom trust validation. Now,
everything works fine but the problem is precisely this. It works fine
even when if I spec
20 matches
Mail list logo