KnowledgeHub
Questions
Tags
Users
Search
Alex Rivera
|
Logout
Edit Question
Title
Body
Does java's TrustManager implementation ignore if a certificate has expired? I tried the following: - Using keytool and parameter -startdate "1970/01/01 00:00:00" I created a P12 keystore with an expired certificate. - I exported the certificate: Keystore type: PKCS12 Keystore provider: SunJSSE Your keystore contains 1 entry Alias name: fake Creation date: 5 ╠ά± 2011 Entry type: PrivateKeyEntry Certificate chain length: 1 Certificate[1]: Owner: CN=Malicious, OU=Mal, O=Mal, L=Fake, ST=GR, C=GR Issuer: CN=Malicious, OU=Mal, O=Mal, L=Fake, ST=GR, C=GR Serial number: -1c20 Valid from: Thu Jan 01 00:00:00 EET 1970 until: Fri Jan 02 00:00:00 EET 1970 Certificate fingerprints: MD5: A9:BE:3A:3D:45:24:1B:4F:3C:9B:2E:02:E3:57:86:11 SHA1: 21:9D:E1:04:09:CF:10:58:73:C4:62:3C:46:4C:76:A3:81:56:88:4D Signature algorithm name: SHA1withRSA Version: 3 ******************************************* I used this certificate as server certificate for Tomcat. Then using an apache httpClient I connected to tomcat, but first I added the expired certificate to the client's trust-store (using a TrustManager TrustManagerFactory tmf = TrustManagerFactory.getInstance(TrustManagerFactory.getDefaultAlgorithm()); and loading the expired certificate). I was expecting the connection to fail. Instead the connection succeeds. Using System.setProperty("javax.net.debug", "ssl"); I see: *** Found trusted certificate: [ [ Version: V3 Subject: CN=Malicious, OU=Mal, O=Mal, L=Fake, ST=GR, C=GR Signature Algorithm: SHA1withRSA, OID = 1.2.840.113549.1.1.5 Key: Sun RSA public key, 1024 bits modulus: 103505550241486353387352204821576872670551399069981699225523573573463728861649080679830970375409225198088456622953795796973617844800523719355651295538603042548325657233735862777322961575720409897968306234
Tags (comma-separated)
Save Edits
Cancel