The following steps should make this reproducible:

  • Create a jar
  • Create keystore(1) with certificate cert1
  • Sign jar using cert1
  • Create keystore(2) with a different certificate cert2
  • Use webstart-plugin
  • sign jar using cert2
  • maven-jar-signer -verify should fail now

Will get into this asap.

This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators.
For more information on JIRA, see: http://www.atlassian.com/software/jira
--------------------------------------------------------------------- To unsubscribe from this list, please visit: http://xircles.codehaus.org/manage_email

Reply via email to