# HG changeset patch # User ascarpino # Date 1469138886 25200 # Node ID 797c32a7d4e24d3c8e2cff7944652c8c20c7cccc # Parent 745f165bedeeedcf7d985a5f872b8e4dec7363ae 8060224: Enable SHA-1 CertPath Restrictions Reviewed-by: mullan diff -r 745f165bedee -r 797c32a7d4e2 jdk/src/java.base/share/conf/security/java.security --- a/jdk/src/java.base/share/conf/security/java.security Thu Jul 21 07:42:05 2016 -0700 +++ b/jdk/src/java.base/share/conf/security/java.security Thu Jul 21 15:08:06 2016 -0700 @@ -652,8 +652,8 @@ # jdk.certpath.disabledAlgorithms=MD2, DSA, RSA keySize < 2048 # # -jdk.certpath.disabledAlgorithms=MD2, MD5, RSA keySize < 1024, \ - DSA keySize < 1024, EC keySize < 224 +jdk.certpath.disabledAlgorithms=MD2, MD5, SHA1 jdkCA & denyAfter 2017-01-01, \ + RSA keySize < 1024, DSA keySize < 1024, EC keySize < 224 # Algorithm restrictions for Secure Socket Layer/Transport Layer Security # (SSL/TLS/DTLS) processing