Unexpected Security problem.
Posted: Sat May 23, 2015 7:20 pm
running on Linux Mint 17
Java 8_45
Firefox 37
I've been developing and running the applet for a couple weeks with no security problems. It is self signed and I put the host site in the java exception list. For dev I've been running it off my localhost apache http and tomcat server.
Yesterday I moved the applet my clients server so they could test it in house. I got a security exception so put the address in the sitelist and it still didn't run. Thats odd I thought.
I then tried running it on my localhost server that has been fine for weeks and got the same exception! That's really odd I thought. I cleared the Java(8_45) cache, browser(firefox) cache, same result. rebuilt the applet same result. I only ran it to compare the console output of a successful load vs an unsuccessful load! What now?
I then built the untouched oxygen sample applet mySample and tried to load that, same exception!
In the java console during the applet loading I found two jars that may be causing the problem. I don't know because I never examined the log of a successful load of the applet?
I'm at my wits end here.
here is the output of signing the oxygen-xerces jar. Its long so here is a link https://spideroak.com/storage/ONSGK4TSN ... 6e984728b4
Java 8_45
Firefox 37
I've been developing and running the applet for a couple weeks with no security problems. It is self signed and I put the host site in the java exception list. For dev I've been running it off my localhost apache http and tomcat server.
Yesterday I moved the applet my clients server so they could test it in house. I got a security exception so put the address in the sitelist and it still didn't run. Thats odd I thought.
I then tried running it on my localhost server that has been fine for weeks and got the same exception! That's really odd I thought. I cleared the Java(8_45) cache, browser(firefox) cache, same result. rebuilt the applet same result. I only ran it to compare the console output of a successful load vs an unsuccessful load! What now?
I then built the untouched oxygen sample applet mySample and tried to load that, same exception!
In the java console during the applet loading I found two jars that may be causing the problem. I don't know because I never examined the log of a successful load of the applet?
andcache: signed entry "javax/xml/namespace/" missing from jar http://127.0.0.1:8080/editor-1/lib/oxyg ... 17.0.0.jar
cache: signed entry "org/xml/sax/" missing from jar http://127.0.0.1:8080/editor-1/lib/oxyg ... 17.0.0.jar
cache: signed entry "javax/xml/validation/" missing from jar http://127.0.0.1:8080/editor-1/lib/oxyg ... 17.0.0.jar
cache: signed entry "javax/xml/datatype/" missing from jar http://127.0.0.1:8080/editor-1/lib/oxyg ... 17.0.0.jar
cache: signed entry "javax/xml/transform/" missing from jar http://127.0.0.1:8080/editor-1/lib/oxyg ... 17.0.0.jar
cache: signed entry "javax/xml/xpath/" missing from jar http://127.0.0.1:8080/editor-1/lib/oxyg ... 17.0.0.jar
cache: signed entry "javax/xml/parsers/" missing from jar http://127.0.0.1:8080/editor-1/lib/oxyg ... 17.0.0.jar
cache: signed entry "javax/xml/stream/" missing from jar http://127.0.0.1:8080/editor-1/lib/oxyg ... 17.0.0.jar
cache: Create from verifier: JarSigningData{hasOnlySignedEntries=true, hasSingleCodeSource=true, hasMissingSignedEntries=true}
I get the same entries in my applet and the sample appletcache: signed entry "org/apache/xmlcommons/Version" missing from jar http://localhost:8080/editor-1/lib/xml-apis-1.4.01.jar
cache: Create from verifier: JarSigningData{hasOnlySignedEntries=true, hasSingleCodeSource=true, hasMissingSignedEntries=true}
cache: Upgrade of entry done
I'm at my wits end here.
here is the output of signing the oxygen-xerces jar. Its long so here is a link https://spideroak.com/storage/ONSGK4TSN ... 6e984728b4