8060224: Enable SHA-1 CertPath Restrictions
authorascarpino
Thu, 21 Jul 2016 15:08:06 -0700
changeset 39767 797c32a7d4e2
parent 39766 745f165bedee
child 39768 8de55c86daa2
child 40189 a72c2c15df00
8060224: Enable SHA-1 CertPath Restrictions Reviewed-by: mullan
jdk/src/java.base/share/conf/security/java.security
--- a/jdk/src/java.base/share/conf/security/java.security	Thu Jul 21 07:42:05 2016 -0700
+++ b/jdk/src/java.base/share/conf/security/java.security	Thu Jul 21 15:08:06 2016 -0700
@@ -652,8 +652,8 @@
 #   jdk.certpath.disabledAlgorithms=MD2, DSA, RSA keySize < 2048
 #
 #
-jdk.certpath.disabledAlgorithms=MD2, MD5, RSA keySize < 1024, \
-    DSA keySize < 1024, EC keySize < 224
+jdk.certpath.disabledAlgorithms=MD2, MD5, SHA1 jdkCA & denyAfter 2017-01-01, \
+    RSA keySize < 1024, DSA keySize < 1024, EC keySize < 224
 
 # Algorithm restrictions for Secure Socket Layer/Transport Layer Security
 # (SSL/TLS/DTLS) processing