I can't find any SymmetricBindingBuilder.java nor jar files in the rampart source package; are you confident this is the correct package?
The description of librampart0 indicates it is to be used with Axis2/c -- if you're performing audits, I suspect that would be a fruitful place to start. I reported SSL vulnerabilities to them 1.5 years ago and never got a response. I suspect security is not a top priority for these projects. Thanks ** Information type changed from Private Security to Public ** Changed in: rampart (Ubuntu) Status: New => Invalid ** Information type changed from Public to Public Security -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1409124 Title: BUG - Use of a Broken or Risky Cryptographic Algorithm - SymmetricBindingBuilder.java 753 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/rampart/+bug/1409124/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs