This is an automated email from the ASF dual-hosted git repository.

markt pushed a commit to branch 8.5.x
in repository https://gitbox.apache.org/repos/asf/tomcat.git


The following commit(s) were added to refs/heads/8.5.x by this push:
     new e5fce85  Switch to Java 7 version of JSign 3.1 to pick up fix for 
SHA-512 sigs
e5fce85 is described below

commit e5fce85d1018559f9e10d412cda297e0c222cdeb
Author: Mark Thomas <ma...@apache.org>
AuthorDate: Fri Jun 11 10:00:09 2021 +0100

    Switch to Java 7 version of JSign 3.1 to pick up fix for SHA-512 sigs
---
 build.properties.default   | 19 ++++++++++---------
 webapps/docs/changelog.xml |  8 ++++++++
 2 files changed, 18 insertions(+), 9 deletions(-)

diff --git a/build.properties.default b/build.properties.default
index 3d191fd..0c6c477 100644
--- a/build.properties.default
+++ b/build.properties.default
@@ -294,15 +294,16 @@ findbugs.home=${base.path}/spotbugs-${findbugs.version}
 findbugs.jar=${findbugs.home}/lib/spotbugs-ant.jar
 
findbugs.loc=${base-maven.loc}/com/github/spotbugs/spotbugs/${findbugs.version}/spotbugs-${findbugs.version}.tgz
 
-# ----- JSign, version 2.1 -----
-# JSign 3.0 onwards required Java 8 so use 2.1
-jsign.version=2.1
+# ----- JSign, version 3.1 -----
+# JSign 3.0 onwards requires Java 8 by default
+# Use Java 7 build
+jsign.version=3.1
 
-# checksums for JSign 2.1
+# checksums for JSign 3.1
 jsign.checksum.enable=true
-jsign.checksum.algorithm=MD5|SHA-1
-jsign.checksum.value=3bfcdc43b6e3d6438af6907b79f2ae3a|473378d211a1ecd28400503f3c2556963da0e626
+jsign.checksum.algorithm=SHA-512
+jsign.checksum.value=481a6e7276688363106ee3492da52807577822b8114b13804df796cd143f479a50d0864215f63b9bb8120a85b2f6185b2845974872d11ff070407dd01879bb0e
 
-jsign.home=${base.path}/jsign-${jsign.version}
-jsign.jar=${jsign.home}/jsign-${jsign.version}.jar
-jsign.loc=${base-maven.loc}/net/jsign/jsign/${jsign.version}/jsign-${jsign.version}.jar
+jsign.home=${base.path}/jsign-${jsign.version}-java7
+jsign.jar=${jsign.home}/jsign-${jsign.version}-java7.jar
+jsign.loc=https://github.com/ebourg/jsign/releases/download/${jsign.version}/jsign-${jsign.version}-java7.jar
diff --git a/webapps/docs/changelog.xml b/webapps/docs/changelog.xml
index 5018f42..084a2fa 100644
--- a/webapps/docs/changelog.xml
+++ b/webapps/docs/changelog.xml
@@ -105,6 +105,14 @@
   issues do not "pop up" wrt. others).
 -->
 <section name="Tomcat 8.5.68 (schultz)" rtext="in development">
+  <subsection name="Other">
+    <changelog>
+      <update>
+        Update to the Java 7 compatible build of JSign 3.1 to pick up a fix for
+        SHA-512 signatures. (markt)
+      </update>
+    </changelog>
+  </subsection>
 </section>
 <section name="Tomcat 8.5.67 (schultz)" rtext="release in progress">
   <subsection name="Catalina">

---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org

Reply via email to