it's Oracle update day

Cantor, Scott cantor.2 at osu.edu
Thu Apr 19 09:30:12 EDT 2018


> * The secure validation mode of the XML Signature implementation has been
> enhanced to restrict EC keys less than 224 bits by default. The secure
> validation mode is enabled either by setting the property
> org.jcp.xml.dsig.secureValidation to true with the
> javax.xml.crypto.XMLCryptoContext.setProperty() method, or by running
> the code with a SecurityManager.

We don't rely on their signature code anywhere.

-- Scott



More information about the dev mailing list