Java 8u72 / MD5 certificates

Cantor, Scott cantor.2 at osu.edu
Sat Jan 23 13:03:10 EST 2016


Just an FYI in case anybody else is running SPs dating from the turn of the millennium, if you have any MD5 certs lying around in metadata, Oracle just slipped a rule into the policy file in the latest Java 8 patch that blocks use of MD5 certs for client TLS or trust path processing in Java.

It doesn't break use of the certificates to get an encryption key, so it's just a SOAP issue. I don't really know how or why I still had an SP using an MD5 client certificate, but it's a very old system (not the SP itself, just the cert).

-- Scott



More information about the users mailing list