Java 8u72 / MD5 certificates
Cantor, Scott
cantor.2 at osu.edu
Sat Jan 23 13:03:10 EST 2016
Just an FYI in case anybody else is running SPs dating from the turn of the millennium, if you have any MD5 certs lying around in metadata, Oracle just slipped a rule into the policy file in the latest Java 8 patch that blocks use of MD5 certs for client TLS or trust path processing in Java.
It doesn't break use of the certificates to get an encryption key, so it's just a SOAP issue. I don't really know how or why I still had an SP using an MD5 client certificate, but it's a very old system (not the SP itself, just the cert).
-- Scott
More information about the users
mailing list