[security-dev 00086]: hg: jdk7/jsn/jdk: 2 new changesets

2008-03-05 Thread weijun . wang
Changeset: d842462572a9 Author:weijun Date: 2008-03-05 22:15 +0800 URL: http://hg.openjdk.java.net/jdk7/jsn/jdk/rev/d842462572a9 6590930: reed/write does not match for ccache Summary: Add null-awareness to ccache read Reviewed-by: valeriep !

[security-dev 00099]: hg: jdk7/jsn/jdk: 6634644: broken fragment, should use @link

2008-03-08 Thread weijun . wang
Changeset: ac695089ccc5 Author:weijun Date: 2008-03-08 22:49 +0800 URL: http://hg.openjdk.java.net/jdk7/jsn/jdk/rev/ac695089ccc5 6634644: broken fragment, should use @link Reviewed-by: mullan ! src/share/classes/javax/security/cert/X509Certificate.java

[security-dev 00251]: hg: jdk7/jsn/jdk: 6709758: keytool default cert fingerprint algorithm should be SHA1, not MD5

2008-07-27 Thread weijun . wang
Changeset: 9655476d50f4 Author:weijun Date: 2008-07-27 19:16 +0800 URL: http://hg.openjdk.java.net/jdk7/jsn/jdk/rev/9655476d50f4 6709758: keytool default cert fingerprint algorithm should be SHA1, not MD5 Reviewed-by: mullan, xuelei !

[security-dev 00298]: hg: jdk7/jsn/jdk: 6740833: krb5.conf does not accept kdc=hostname (no spaces around =)

2008-09-08 Thread weijun . wang
Changeset: bcb61dfc8514 Author:weijun Date: 2008-09-08 14:17 +0800 URL: http://hg.openjdk.java.net/jdk7/jsn/jdk/rev/bcb61dfc8514 6740833: krb5.conf does not accept kdc=hostname (no spaces around =) Reviewed-by: xuelei ! src/share/classes/sun/security/krb5/Config.java

[security-dev 00346]: hg: jdk7/jsn/jdk: 6706974: Add krb5 test infrastructure

2008-10-16 Thread weijun . wang
Changeset: 3f051f3ba5bb Author:weijun Date: 2008-10-17 13:02 +0800 URL: http://hg.openjdk.java.net/jdk7/jsn/jdk/rev/3f051f3ba5bb 6706974: Add krb5 test infrastructure Reviewed-by: valeriep + test/sun/security/krb5/auto/Action.java + test/sun/security/krb5/auto/BasicKrb5Test.java +

[security-dev 00349]: hg: jdk7/jsn/jdk: 6761072: new krb5 tests fail on multiple platforms

2008-10-19 Thread weijun . wang
Changeset: 0bf6c9c6fdc5 Author:weijun Date: 2008-10-20 10:32 +0800 URL: http://hg.openjdk.java.net/jdk7/jsn/jdk/rev/0bf6c9c6fdc5 6761072: new krb5 tests fail on multiple platforms Reviewed-by: xuelei ! test/sun/security/krb5/auto/BasicKrb5Test.java !

[security-dev 00360]: JGSS/krb5: Too strict Krb5LoginModule options validation

2008-10-21 Thread Weijun Wang
Hi All Currently we have this check inside Krb5LoginModule: private void validateConfiguration() throws LoginException { if (doNotPrompt !useTicketCache !useKeyTab) throw new LoginException (Configuration Error + - either doNotPrompt

[security-dev 00400]: hg: jdk7/tl/jdk: 2 new changesets

2008-11-12 Thread weijun . wang
Changeset: d2f96992b77b Author:weijun Date: 2008-11-12 16:00 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/d2f96992b77b 6733095: Failure when SPNEGO request non-Mutual Reviewed-by: valeriep ! src/share/classes/sun/security/jgss/GSSContextImpl.java !

[security-dev 00429]: Request for comment: How to enable credentials delegation in HTTP Negotiate?

2008-11-24 Thread Weijun Wang
Hi All The current implementation of HTTP Negotiate authentication has not enabled credential delegation (it simply acquires a new one using either a cached TGT or username/password from Authenticator). This means that in a multi-tier application, a middle tier cannot start an HTTP request (to

[security-dev 00659]: hg: jdk7/tl/jdk: 6705872: SecureRandom number init is taking too long on a java.io.tmpdir with a large number of files.

2009-03-03 Thread weijun . wang
Changeset: a8d9e8cb38bb Author:weijun Date: 2009-03-04 15:09 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/a8d9e8cb38bb 6705872: SecureRandom number init is taking too long on a java.io.tmpdir with a large number of files. Reviewed-by: xuelei, alanb !

[security-dev 00681]: keytool: -import reply different when length is different

2009-03-10 Thread Weijun Wang
Hi In keytool's installReply(), there is: if (replyCerts.length == 1) { // single-cert reply newChain = establishCertChain(userCert, replyCerts[0]); } else { // cert-chain reply (e.g., PKCS#7) newChain = validateReply(alias,

[security-dev 00685]: hg: jdk7/tl/jdk: 2 new changesets

2009-03-12 Thread weijun . wang
Changeset: 9d5cce463fa0 Author:weijun Date: 2009-03-13 09:20 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/9d5cce463fa0 6815182: GSSAPI/SPNEGO does not work with server using MIT Kerberos library Reviewed-by: valeriep !

[security-dev 00699]: hg: jdk7/tl/jdk: 6819272: keytool -importcert should read the whole input

2009-03-18 Thread weijun . wang
Changeset: 87acd36bd847 Author:weijun Date: 2009-03-19 11:17 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/87acd36bd847 6819272: keytool -importcert should read the whole input Reviewed-by: xuelei ! src/share/classes/sun/security/tools/KeyTool.java +

[security-dev 00710]: hg: jdk7/tl/jdk: 6820606: keytool can generate serialno more randomly

2009-03-23 Thread weijun . wang
Changeset: 74fe20f0e49b Author:weijun Date: 2009-03-23 17:05 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/74fe20f0e49b 6820606: keytool can generate serialno more randomly Reviewed-by: xuelei ! src/share/classes/sun/security/tools/KeyTool.java !

[security-dev 00722]: hg: jdk7/tl/jdk: 6802846: jarsigner needs enhanced cert validation(options)

2009-03-26 Thread weijun . wang
Changeset: b752110df530 Author:weijun Date: 2009-03-27 11:05 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/b752110df530 6802846: jarsigner needs enhanced cert validation(options) Reviewed-by: xuelei ! src/share/classes/sun/security/tools/JarSigner.java !

[security-dev 00731]: hg: jdk7/tl/jdk: 6825352: support self-issued certificate in keytool

2009-04-02 Thread weijun . wang
Changeset: ee75d1fac0ca Author:weijun Date: 2009-04-03 11:36 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/ee75d1fac0ca 6825352: support self-issued certificate in keytool Reviewed-by: xuelei ! src/share/classes/sun/security/tools/KeyTool.java +

[security-dev 00747]: hg: jdk7/tl/jdk: 6714845: Quotes in Kerberos configuration file are included in the values

2009-04-09 Thread weijun . wang
Changeset: 8d37331265ae Author:weijun Date: 2009-04-09 15:32 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/8d37331265ae 6714845: Quotes in Kerberos configuration file are included in the values Reviewed-by: xuelei ! src/share/classes/sun/security/krb5/Config.java +

[security-dev 00749]: Code review request: Undefined requesting URL in java.net.Authenticator.getPasswordAuthentication()

2009-04-12 Thread Weijun Wang
Hi Valerie and Networking guys Please take a review at this bug fix: http://cr.openjdk.java.net/~weijun/6578647/webrev.00/ The bug is http://bugs.sun.com/bugdatabase/view_bug.do?bug_id=6578647 The bug report says that no URL-related info is available in Authenticator when using

[security-dev 00755]: hg: jdk7/tl/jdk: 6830658: Changeset 897b2d42995a breaks the fastdebug build in NativeCreds.c

2009-04-15 Thread weijun . wang
Changeset: 33e06332c9d4 Author:weijun Date: 2009-04-16 11:16 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/33e06332c9d4 6830658: Changeset 897b2d42995a breaks the fastdebug build in NativeCreds.c Reviewed-by: tbell ! src/windows/native/sun/security/krb5/NativeCreds.c

[security-dev 00756]: Re: Code review request: Undefined requesting URL in java.net.Authenticator.getPasswordAuthentication()

2009-04-16 Thread Weijun Wang
, putting two Kerberos KDC, one HTTP server, one proxy server in a single regression test is fun! Thanks Mx On Apr 14, 2009, at 8:55 PM, Max (Weijun) Wang wrote: On Apr 14, 2009, at 5:59 PM, Christopher Hegarty - Sun Microsystems Ireland wrote: Hi Max, I only looked at the networking

[security-dev 00858]: Re: Code review request: 6813340: X509Factory should not depend on is.available()==0

2009-05-25 Thread Weijun Wang
The new webrev is at http://cr.openjdk.java.net/~weijun/6813340/webrev.03 Changes compared to last webrev is: diff -r 59db2c7c37fa src/share/classes/sun/security/provider/X509Factory.java --- a/src/share/classes/sun/security/provider/X509Factory.java +++

[security-dev 00887]: hg: jdk7/tl/jdk: 6578647: Undefined requesting URL in java.net.Authenticator.getPasswordAuthentication()

2009-06-09 Thread weijun . wang
Changeset: 8f405b65ddac Author:weijun Date: 2009-06-09 14:17 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/8f405b65ddac 6578647: Undefined requesting URL in java.net.Authenticator.getPasswordAuthentication() Reviewed-by: chegar, valeriep !

[security-dev 00903]: hg: jdk7/tl/jdk: 6849275: enhance krb5 reg tests

2009-06-17 Thread weijun . wang
Changeset: bc2c9dbdcc70 Author:weijun Date: 2009-06-17 15:26 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/bc2c9dbdcc70 6849275: enhance krb5 reg tests Reviewed-by: xuelei ! test/sun/security/krb5/auto/CrossRealm.java ! test/sun/security/krb5/auto/HttpNegotiateServer.java

[security-dev 00904]: hg: jdk7/tl/jdk: 6712755: jarsigner fails to sign itextasian.jar since 1.5.0_b14, it works with 1.5.0_13

2009-06-17 Thread weijun . wang
Changeset: 863351d5d244 Author:weijun Date: 2009-06-18 11:12 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/863351d5d244 6712755: jarsigner fails to sign itextasian.jar since 1.5.0_b14, it works with 1.5.0_13 Reviewed-by: mullan !

[security-dev 00941]: hg: jdk7/tl/jdk: 6855671: DerOutputStream encodes negative integer incorrectly

2009-06-29 Thread weijun . wang
Changeset: 605d3fa6764e Author:weijun Date: 2009-06-30 11:55 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/605d3fa6764e 6855671: DerOutputStream encodes negative integer incorrectly Reviewed-by: xuelei ! src/share/classes/sun/security/util/DerOutputStream.java +

[security-dev 00949]: Re: code review request 6853793: OutOfMemoryError in sun.security.provider.certpath.OCSPChecker.check

2009-07-02 Thread Weijun Wang
; total += count; } Weijun Wang wrote: I understand what the code means. It either reads contentLength bytes of data, or, if it's -1, reads until EOF. However, I guess it would look simpler if you use only one while(read): if (contentLength == -1) { resp = new byte[contentLength

[security-dev 00968]: hg: jdk7/tl/jdk: 2 new changesets

2009-07-07 Thread weijun . wang
Changeset: 1175f872a968 Author:weijun Date: 2009-07-08 12:07 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/1175f872a968 6857802: GSS getRemainingInitLifetime method returns milliseconds not seconds Reviewed-by: xuelei !

[security-dev 00998]: CCAPI in Java

2009-07-21 Thread Weijun Wang
Hi Shawn Earlier this year, you've asked me about supporting CCAPI in Java. At the time, our Java JGSS provider only support the FILE ccache reading. (We do have a native bridge to GSSAPI but that provider is not turned on by default). I'm creating a native bridge to CCAPI now. Some questions:

[security-dev 00999]: hg: jdk7/tl/jdk: 4 new changesets

2009-07-22 Thread weijun . wang
Changeset: 81e3117803a5 Author:weijun Date: 2009-07-22 16:39 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/81e3117803a5 6858589: more changes to Config on system properties Reviewed-by: valeriep ! src/share/classes/sun/security/krb5/Config.java !

[security-dev 01032]: hg: jdk7/tl/jdk: 6867231: Regression: jdk/test/sun/security/krb5/ConfPlusProp.java error against jdk7/pit/b68

2009-07-31 Thread weijun . wang
Changeset: 0c58a7b6b978 Author:weijun Date: 2009-07-31 16:21 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/0c58a7b6b978 6867231: Regression: jdk/test/sun/security/krb5/ConfPlusProp.java error against jdk7/pit/b68 Reviewed-by: xuelei !

[security-dev 01034]: hg: jdk7/tl/jdk: 6867687: keytool's standard.sh test timeout sometimes

2009-08-01 Thread weijun . wang
Changeset: 2536ab04dc68 Author:weijun Date: 2009-08-02 13:40 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/2536ab04dc68 6867687: keytool's standard.sh test timeout sometimes Reviewed-by: xuelei ! test/sun/security/tools/keytool/standard.sh

[security-dev 01064]: hg: jdk7/tl/jdk: 3 new changesets

2009-08-10 Thread weijun . wang
Changeset: 5439d705c04e Author:weijun Date: 2009-08-11 12:15 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/5439d705c04e 6866479: libzip.so caused JVM to crash when running jarsigner Reviewed-by: mullan ! src/share/classes/sun/security/tools/JarSigner.java +

[security-dev 01065]: hg: jdk7/tl/jdk: 6868867: Test: sun/security/tools/keytool/standard.sh fails under windows/cygwin

2009-08-11 Thread weijun . wang
Changeset: efe2d2a55b3b Author:weijun Date: 2009-08-11 15:36 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/efe2d2a55b3b 6868867: Test: sun/security/tools/keytool/standard.sh fails under windows/cygwin Reviewed-by: wetmore ! src/share/classes/sun/security/tools/KeyTool.java

[security-dev 01090]: hg: jdk7/tl/jdk: 6829785: TextCallbackHandler does not honor PasswordCallback.isEchoOn()

2009-08-17 Thread weijun . wang
Changeset: 8414927b41d8 Author:weijun Date: 2009-08-18 10:20 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/8414927b41d8 6829785: TextCallbackHandler does not honor PasswordCallback.isEchoOn() Reviewed-by: mullan !

[security-dev 01112]: hg: jdk7/tl/jdk: 6875033: regression: test of 6867665 fail

2009-08-24 Thread weijun . wang
Changeset: dbcc1f13e4fd Author:weijun Date: 2009-08-24 18:37 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/dbcc1f13e4fd 6875033: regression: test of 6867665 fail Reviewed-by: xuelei ! test/sun/security/krb5/ktab/HighestKvno.java

[security-dev 01121]: hg: jdk7/tl/jdk: 6868864: Kerberos tests fail under windows/cygwin

2009-08-25 Thread weijun . wang
Changeset: 2607e571a6d5 Author:weijun Date: 2009-08-26 12:17 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/2607e571a6d5 6868864: Kerberos tests fail under windows/cygwin Reviewed-by: wetmore ! test/sun/security/krb5/auto/basic.sh

[security-dev 01173]: hg: jdk7/tl/jdk: 2 new changesets

2009-09-04 Thread weijun . wang
Changeset: ee5300e1835a Author:weijun Date: 2009-09-04 14:58 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/ee5300e1835a 6876328: different names for the same digest algorithms breaks jarsigner Reviewed-by: mullan ! src/share/classes/sun/security/tools/JarSigner.java +

[security-dev 01238]: hg: jdk7/tl/jdk: 6877357: IPv6 address does not work

2009-09-21 Thread weijun . wang
Changeset: 81dffe63c913 Author:weijun Date: 2009-09-22 10:01 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/81dffe63c913 6877357: IPv6 address does not work Reviewed-by: xuelei, alanb ! src/share/classes/sun/security/krb5/KrbKdcReq.java + test/sun/security/krb5/IPv6.java

[security-dev 01252]: hg: jdk7/tl/jdk: 6885166: regression test for 6877357 (IPv6 address does not work) error (timed out)

2009-09-24 Thread weijun . wang
Changeset: bd928aefe692 Author:weijun Date: 2009-09-24 21:35 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/bd928aefe692 6885166: regression test for 6877357 (IPv6 address does not work) error (timed out) Reviewed-by: xuelei ! test/sun/security/krb5/IPv6.java

[security-dev 01266]: hg: jdk7/tl/jdk: 4 new changesets

2009-10-02 Thread weijun . wang
Changeset: 527ad9cbc9cf Author:weijun Date: 2009-10-02 18:44 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/527ad9cbc9cf 6324292: keytool -help is unhelpful Reviewed-by: xuelei, mullan ! src/share/classes/sun/security/tools/KeyTool.java !

[security-dev 01330]: hg: jdk7/tl/jdk: 6870812: enhance security tools to use ECC algorithms

2009-10-20 Thread weijun . wang
Changeset: 0d7c64c023c6 Author:weijun Date: 2009-10-21 08:17 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/0d7c64c023c6 6870812: enhance security tools to use ECC algorithms Reviewed-by: vinnie, mullan ! src/share/classes/java/util/jar/JarFile.java !

[security-dev 01348]: hg: jdk7/tl/jdk: 6894534: SeedGenerator shouldn't require java.nio.file to be present

2009-10-29 Thread weijun . wang
Changeset: a1923ebcd61b Author:weijun Date: 2009-10-30 11:28 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/a1923ebcd61b 6894534: SeedGenerator shouldn't require java.nio.file to be present Reviewed-by: alanb ! src/share/classes/sun/security/provider/SeedGenerator.java

[security-dev 01417]: hg: jdk7/tl/jdk: 3 new changesets

2009-11-26 Thread weijun . wang
Changeset: 7871897537b1 Author:weijun Date: 2009-11-27 08:51 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/7871897537b1 6853328: Support OK-AS-DELEGATE flag Reviewed-by: valeriep ! src/share/classes/com/sun/security/jgss/ExtendedGSSContext.java !

[security-dev 01450]: hg: jdk7/tl/jdk: 6908628: ObjectIdentifier s11n test fails

2009-12-08 Thread weijun . wang
Changeset: db5c77621c6b Author:weijun Date: 2009-12-09 11:15 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/db5c77621c6b 6908628: ObjectIdentifier s11n test fails Reviewed-by: xuelei ! test/sun/security/util/Oid/S11N.sh

[security-dev 01489]: hg: jdk7/tl/jdk: 2 new changesets

2010-01-04 Thread weijun . wang
Changeset: ef9774dc4f5a Author:weijun Date: 2010-01-05 10:40 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/ef9774dc4f5a 6895424: RFC 5653 Reviewed-by: valeriep ! src/share/classes/org/ietf/jgss/GSSName.java ! src/share/classes/sun/security/jgss/GSSManagerImpl.java !

[security-dev 01559]: hg: jdk7/tl/jdk: 6919610: KeyTabInputStream uses static field for per-instance value

2010-01-26 Thread weijun . wang
Changeset: 558f2a424bfa Author:weijun Date: 2010-01-26 17:03 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/558f2a424bfa 6919610: KeyTabInputStream uses static field for per-instance value Reviewed-by: mullan !

[security-dev 01693]: hg: jdk7/tl/jdk: 6868865: Test: sun/security/tools/jarsigner/oldsig.sh fails under all platforms

2010-03-16 Thread weijun . wang
Changeset: 0500f7306cbe Author:weijun Date: 2010-03-17 09:55 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/0500f7306cbe 6868865: Test: sun/security/tools/jarsigner/oldsig.sh fails under all platforms Reviewed-by: wetmore ! test/sun/security/tools/jarsigner/oldsig.sh

[security-dev 01694]: hg: jdk7/tl/jdk: 6829283: HTTP/Negotiate: Autheticator triggered again when user cancels the first one

2010-03-18 Thread weijun . wang
Changeset: 2796f839e337 Author:weijun Date: 2010-03-18 18:26 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/2796f839e337 6829283: HTTP/Negotiate: Autheticator triggered again when user cancels the first one Reviewed-by: chegar !

[security-dev 01714]: '\0' in alias name of a pkcs11 keystore

2010-03-18 Thread Weijun Wang
Hi Valerie As described in http://forums.sun.com/thread.jspa?threadID=5432248, customer's pkcs11 keystore has aliases ended with '\0'. Is this something we should fix on the Java side? Thanks Max

Re: CR 6939248/7 Created, P4 java/classes_secu Jarsigner can't extract Extended Key Usage from Timestamp Reply currectly

2010-04-12 Thread Weijun Wang
Hi Xuelei and Sean Please take a review on the fix for OpenJDK: http://cr.openjdk.java.net/~weijun/6939248/webrev.00 Note that I've added some check: 1. response cert null check 2. extension isCritical check About the test: 1. Since keytool can now generate extensions, binary keystore is

hg: jdk7/tl/jdk: 6937978: let keytool -gencert generate the chain

2010-04-15 Thread weijun . wang
Changeset: db4fd2fdf196 Author:weijun Date: 2010-04-16 10:06 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/db4fd2fdf196 6937978: let keytool -gencert generate the chain Reviewed-by: mullan ! src/share/classes/sun/security/tools/KeyTool.java !

hg: jdk7/tl/jdk: 6939248: Jarsigner can't extract Extended Key Usage from Timestamp Reply correctly

2010-04-15 Thread weijun . wang
Changeset: 0d989dc383d3 Author:weijun Date: 2010-04-16 10:13 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/0d989dc383d3 6939248: Jarsigner can't extract Extended Key Usage from Timestamp Reply correctly Reviewed-by: xuelei, mullan !

hg: jdk7/tl/jdk: 6944847: native gss lib names on linux

2010-04-20 Thread weijun . wang
Changeset: 97fb6f6d230a Author:weijun Date: 2010-04-20 19:30 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/97fb6f6d230a 6944847: native gss lib names on linux Reviewed-by: valeriep ! src/share/classes/sun/security/jgss/wrapper/SunNativeProvider.java +

hg: jdk7/tl/jdk: 6856069: PrincipalName.clone() does not invoke super.clone()

2010-04-21 Thread weijun . wang
Changeset: edde2f60415b Author:weijun Date: 2010-04-22 12:45 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/edde2f60415b 6856069: PrincipalName.clone() does not invoke super.clone() Reviewed-by: chegar ! src/share/classes/sun/security/krb5/PrincipalName.java +

code review request: 6948287 KDC test strange kvno

2010-04-28 Thread Weijun Wang
Hi Please take a review at this test bug: http://cr.openjdk.java.net/~weijun/6948287/webrev.00 Thanks Max *Change Request ID*: 6948287 *Synopsis*: KDC test strange kvno Keywords: noreg-self === *Description* In

hg: jdk7/tl/jdk: 2 new changesets

2010-04-29 Thread weijun . wang
Changeset: b833a422c776 Author:weijun Date: 2010-04-29 15:50 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/b833a422c776 6947487: use HexDumpEncoder.encodeBuffer() Reviewed-by: mullan ! src/share/classes/com/sun/security/auth/module/Krb5LoginModule.java !

hg: jdk7/tl/jdk: 6948909: Jarsigner removes MANIFEST.MF info for badly packages jar's

2010-05-05 Thread weijun . wang
Changeset: 3d51799b65a9 Author:weijun Date: 2010-05-06 11:26 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/3d51799b65a9 6948909: Jarsigner removes MANIFEST.MF info for badly packages jar's Reviewed-by: mullan, xuelei ! src/share/classes/sun/security/tools/JarSigner.java +

hg: jdk7/tl/jdk: 6890876: jarsigner can add CRL info into signed jar

2010-05-05 Thread weijun . wang
Changeset: 8834c3633f0b Author:weijun Date: 2010-05-06 13:42 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/8834c3633f0b 6890876: jarsigner can add CRL info into signed jar Reviewed-by: mullan ! src/share/classes/com/sun/jarsigner/ContentSignerParameters.java !

Re: Please review fix for 6951599 (Rename package of security tools for modularization)

2010-05-14 Thread Weijun Wang
On May 14, 2010, at 2:40 PM, Mandy Chung wrote: Hi Max, Wang Weijun wrote: Hi Mandy Sorry for late comment. My email client on Nokia E71 keeps crashing. (Hope it's good this time). It's good. Thanks for the comment. I'm quite sure there are people out there calling KeyTool the

code review request: 6882687 KerberosTime too imprecise

2010-05-17 Thread Weijun Wang
Hi Valerie A new bug 6950930 filed for the same problem. So ping again. Webrev small update at -- http://cr.openjdk.java.net/~weijun/6882687/webrev.01 Changes: 1. 2009 - 2010 2. new fields now private final Thanks Max On Sep 17, 2009, at 1:46 AM, Max (Weijun) Wang wrote: Hi Valerie

hg: jdk7/tl/jdk: 2 new changesets

2010-05-23 Thread weijun . wang
Changeset: d01726854317 Author:weijun Date: 2010-05-24 09:28 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/d01726854317 6948803: CertPath validation regression caused by SHA1 replacement root and MD2 disable feature Reviewed-by: xuelei, mullan !

hg: jdk7/tl/jdk: 2 new changesets

2010-05-23 Thread weijun . wang
Changeset: ff9cc9789bb3 Author:weijun Date: 2010-05-24 09:37 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/ff9cc9789bb3 6882687: KerberosTime too imprecise Reviewed-by: valeriep ! src/share/classes/sun/security/krb5/internal/KerberosTime.java +

hg: jdk7/tl/jdk: 6932525: Incorrect encryption types of KDC_REQ_BODY of AS-REQ with pre-authentication

2010-05-23 Thread weijun . wang
Changeset: ba95fd03440b Author:weijun Date: 2010-05-24 10:05 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/ba95fd03440b 6932525: Incorrect encryption types of KDC_REQ_BODY of AS-REQ with pre-authentication Reviewed-by: valeriep !

hg: jdk7/tl/jdk: 6948287: KDC test strange knvo

2010-05-25 Thread weijun . wang
Changeset: 2306564dea3a Author:weijun Date: 2010-05-25 18:20 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/2306564dea3a 6948287: KDC test strange knvo Reviewed-by: xuelei ! test/sun/security/krb5/auto/KDC.java

hg: jdk7/tl/jdk: 6955783: ServiceUnavailableException caught even the secondary DNS is available

2010-05-27 Thread weijun . wang
Changeset: d5939d20b762 Author:weijun Date: 2010-05-27 17:24 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/d5939d20b762 6955783: ServiceUnavailableException caught even the secondary DNS is available Reviewed-by: vinnie ! src/share/classes/com/sun/jndi/dns/DnsClient.java

code review request: 6844907: krb5 etype order should be from strong to weak

2010-06-01 Thread Weijun Wang
Hi All Please review this webrev: http://cr.openjdk.java.net/~weijun/6844907/webrev.00/ Three notes: 1. The etype order change has effect on keys in a keytab file. In KeyTab.java, I've made the following change: public EncryptionKey[] readServiceKeys(PrincipalName service) {

code review request: 6958026: Problem with PKCS12 keystore

2010-06-02 Thread Weijun Wang
Hi All Please review this code change: http://cr.openjdk.java.net/~weijun/6958026/webrev.00/ Two parts included: 1. Major one: match private key and cert using both keyId and friendlyName. 2. Minor one: add keyId and friendlyName to private keys created by setKeyEntry(alias, byte[],

hg: jdk7/tl/jdk: 6951366: kerberos login failure on win2008 with AD set to win2000 compat mode

2010-06-04 Thread weijun . wang
Changeset: ea8c57ec8409 Author:weijun Date: 2010-06-04 19:28 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/ea8c57ec8409 6951366: kerberos login failure on win2008 with AD set to win2000 compat mode Reviewed-by: valeriep, xuelei !

code review request: 6960894: Better AS-REQ creation and processing

2010-06-13 Thread Weijun Wang
Hi Valerie and Andrew Please review the following webrev: http://cr.openjdk.java.net/~weijun/6960894/webrev.00 The major enhancement is KrbAsReqBuilder which generates AS-REQ, sends it, parses any response, and returns a Credentials object. The other big change is KrbKdcReq, it's no longer

hg: jdk7/tl/jdk: 6959292: regression: cannot login if session key and preauth does not use the same etype

2010-06-16 Thread weijun . wang
Changeset: 3df25d0680f3 Author:weijun Date: 2010-06-17 13:46 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/3df25d0680f3 6959292: regression: cannot login if session key and preauth does not use the same etype Reviewed-by: xuelei, valeriep !

code review request: 6670889: Keystore created under Hindi Locale causing ArrayIndexOutOfBoundsException

2010-07-13 Thread Weijun Wang
6670889: Keystore created under Hindi Locale causing ArrayIndexOutOfBoundsException Webrev: http://cr.openjdk.java.net/~weijun/6670889/webrev.00/ Thanks Max

hg: jdk7/tl/jdk: 6670889: Keystore created under Hindi Locale causing ArrayIndexOutOfBoundsException

2010-07-13 Thread weijun . wang
Changeset: f3a4c1947fd1 Author:weijun Date: 2010-07-13 20:27 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/f3a4c1947fd1 6670889: Keystore created under Hindi Locale causing ArrayIndexOutOfBoundsException Reviewed-by: chegar !

code review request: 6969292: make DNS lookup for realm/kdc really work

2010-07-15 Thread Weijun Wang
Hi Valerie 6969292: make DNS lookup for realm/kdc really work Webrev: http://cr.openjdk.java.net/~weijun/6969292/webrev.00/ We've implemented DNS lookup for realm and kdc for some time, and have made it default turned on in JDK 7. However, it's still not 100% zero-configuration, a krb5.conf

Re: code review request: 6969292: make DNS lookup for realm/kdc really work

2010-07-16 Thread Weijun Wang
Updated webrev: http://cr.openjdk.java.net/~weijun/6969292/webrev.01/ Changes: checkRealm() return null instead of throwing an exception. (Thanks, Alan). Thanks Max On 07/15/2010 02:12 PM, Weijun Wang wrote: Hi Valerie 6969292: make DNS lookup for realm/kdc really work Webrev: http

Re: PKCS11 no longer supported for KeyStore

2010-07-18 Thread Weijun Wang
What platform and openjdk release (or build) are you using? What kind of security providers are specified? When you say regression, is it a regression of an earlier build of openjdk? If I understand correctly, a PKCS #11 security provider is needed to use PKCS11-based keystores. Currently,

hg: jdk7/tl/jdk: 2 new changesets

2010-07-18 Thread weijun . wang
Changeset: 9a1bd20fc71c Author:weijun Date: 2010-07-19 10:02 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/9a1bd20fc71c 6969683: Generify ResolverConfiguration codes Reviewed-by: alanb, chegar ! src/share/classes/com/sun/jndi/dns/DnsContextFactory.java !

Fwd: CR 6972005 Created, P4 jgss/krb5plugin ConfPlusProp.java test failure when DNS has info for realm

2010-07-26 Thread Weijun Wang
Hi Xuelei A regression in test: *Change Request ID*: 6972005 *Synopsis*: ConfPlusProp.java test failure when DNS has info for realm webrev: http://cr.openjdk.java.net/~weijun/6972005/webrev.00/ Thanks Max === *Description* The

hg: jdk7/tl/jdk: 6972005: ConfPlusProp.java test failure when DNS has info for realm

2010-07-26 Thread weijun . wang
Changeset: 402ff3e81922 Author:weijun Date: 2010-07-26 17:21 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/402ff3e81922 6972005: ConfPlusProp.java test failure when DNS has info for realm Reviewed-by: xuelei ! test/sun/security/krb5/ConfPlusProp.java !

Re: code review request: CR 6870947 15 sec delay detecting socket closed condition when a TCP connection is reset by an LDAP server

2010-07-27 Thread Weijun Wang
Fix looks fine. I finally find the ldr.wait(15 * 1000) line. -Max On 07/27/2010 11:50 AM, Xuelei Fan wrote: Hi Weijun, A JNDI bug. webrev: http://cr.openjdk.java.net/~xuelei/6870947/webrev.00/ bug desc: http://bugs.sun.com/bugdatabase/view_bug.do?bug_id=6870947 Thanks, Xuelei

Re: code review request: 6973371: X509Factory should recognize PEM headers

2010-07-31 Thread Weijun Wang
the stream, and throw an exception if it wasn't a certificate. But the current fix ignores non certificate blocks until it finds a certificate or end of stream, right? --Sean On 7/30/10 2:39 AM, Weijun Wang wrote: Hi Sean 6973371: X509Factory should recognize PEM headers Please review

Re: code review request: 6973371: X509Factory should recognize PEM headers

2010-08-01 Thread Weijun Wang
Re-send mail. Probably lost during in a mail server outage. On 07/31/2010 09:46 PM, Weijun Wang wrote: Yes, you're correct. I regard not-working - working a fix, not a regression. Thanks Max On Jul 31, 2010, at 12:46 AM, Sean Mullan wrote: Hi Max, I'm not sure about this change

Re: code review request: 6973371: X509Factory should recognize PEM headers

2010-08-02 Thread Weijun Wang
On 08/03/2010 05:10 AM, Sean Mullan wrote: On 7/31/10 9:46 AM, Weijun Wang wrote: Yes, you're correct. I regard not-working - working a fix, not a regression. I think I would regard it as underspecified. There's nothing in CertificateFactory.generateCertificate that says it skips non

Re: code review request: 6960894: Better AS-REQ creation and processing

2010-08-08 Thread Weijun Wang
now. Thanks Max Thanks, Valerie On 07/21/10 12:32, Valerie (Yu-Ching) Peng wrote: On 06/13/10 08:02, Weijun Wang wrote: Hi Valerie and Andrew Please review the following webrev: http://cr.openjdk.java.net/~weijun/6960894/webrev.00 The major enhancement is KrbAsReqBuilder which

hg: jdk7/tl/jdk: 6976536: Solaris JREs do not have the krb5.kdc.bad.policy configured by default.

2010-08-18 Thread weijun . wang
Changeset: 4abd65f04638 Author:weijun Date: 2010-08-19 11:26 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/4abd65f04638 6976536: Solaris JREs do not have the krb5.kdc.bad.policy configured by default. Reviewed-by: valeriep ! src/share/lib/security/java.security-solaris !

hg: jdk7/tl/jdk: 6921610: 1.6 update 17 and 18 throw java.lang.IndexOutOfBoundsException

2010-08-18 Thread weijun . wang
Changeset: 95bb147c7c33 Author:weijun Date: 2010-08-19 12:24 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/95bb147c7c33 6921610: 1.6 update 17 and 18 throw java.lang.IndexOutOfBoundsException Reviewed-by: vinnie, xuelei ! src/share/classes/com/sun/jndi/ldap/Connection.java

code review request: 6979329: CCacheInputStream fails to read ticket cache files from Kerberos 1.8.1

2010-08-24 Thread Weijun Wang
HI All webrev at -- http://cr.openjdk.java.net/~weijun/6979329/webrev.00/ I'm not sure if there will be other type of non-ticket entries later, so just ignore once an exception is thrown. I'll be glad if there can be more than one code reviewers. Mostly likely this will need to

code review request: 6911951: NTLM should be a supported Java SASL mechanism

2010-08-24 Thread Weijun Wang
Ping again. The webrev is updated: http://cr.openjdk.java.net/~weijun/6911951/webrev.01/ The CCC is about to be finalized: http://ccc.sfbay.sun.com/6911951 Thanks Max On 04/16/2010 11:12 AM, Weijun Wang wrote: Vinnie Please take a review on this webrev: cr.openjdk.java.net

Re: code review request: 6911951: NTLM should be a supported Java SASL mechanism

2010-08-26 Thread Weijun Wang
you any comments on the NTLM changes? On 25/08/2010 06:23, Weijun Wang wrote: Ping again. The webrev is updated: http://cr.openjdk.java.net/~weijun/6911951/webrev.01/ The CCC is about to be finalized: http://ccc.sfbay.sun.com/6911951 Thanks Max On 04/16/2010 11:12 AM, Weijun Wang wrote

code review request: 6845220: Need to update Policytool for Rowset 1.1 and JDBC 4.1 MR added permissions

2010-09-10 Thread Weijun Wang
Hi Lance I've updated policytool to match your new SQLPermission target names, webrev at: http://cr.openjdk.java.net/~weijun/6845220/webrev.00/ It seems there's an extra name setNetworkTimeout (compared with original RFE description) in your latest changeset at:

hg: jdk7/tl/jdk: 6982840: sun/security/tools/jarsigner/emptymanifest.sh fails

2010-09-13 Thread weijun . wang
Changeset: 5c3bad1d7f8a Author:weijun Date: 2010-09-14 10:18 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/5c3bad1d7f8a 6982840: sun/security/tools/jarsigner/emptymanifest.sh fails Reviewed-by: dholmes ! test/sun/security/tools/jarsigner/emptymanifest.sh

hg: jdk7/tl/jdk: 6982971: TEST failure: com/sun/security/sasl/ntlm/NTLMTest.java

2010-09-22 Thread weijun . wang
Changeset: ca630e91d473 Author:weijun Date: 2010-09-23 10:46 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/ca630e91d473 6982971: TEST failure: com/sun/security/sasl/ntlm/NTLMTest.java Reviewed-by: wetmore ! test/com/sun/security/sasl/ntlm/NTLMTest.java

hg: jdk7/tl/jdk: 6986868: TEST failure: sun/security/tools/jarsigner/crl.sh

2010-09-24 Thread weijun . wang
Changeset: 9eb9485ec45b Author:weijun Date: 2010-09-25 10:21 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/9eb9485ec45b 6986868: TEST failure: sun/security/tools/jarsigner/crl.sh Reviewed-by: ohair ! test/sun/security/tools/jarsigner/crl.sh

hg: jdk7/tl/jdk: 6988163: sun.security.util.Resources dup and a keytool doc typo

2010-09-29 Thread weijun . wang
Changeset: 26c6ee936f63 Author:weijun Date: 2010-09-29 15:26 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/26c6ee936f63 6988163: sun.security.util.Resources dup and a keytool doc typo Reviewed-by: xuelei ! src/share/classes/sun/security/tools/KeyTool.java !

hg: jdk7/tl/jdk: 6950546: ktab -d name etype to ktab -d name [-e etype] [kvno | all | old]; ...

2010-10-28 Thread weijun . wang
Changeset: dfce5a0cc460 Author:weijun Date: 2010-10-28 21:14 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/dfce5a0cc460 6950546: ktab -d name etype to ktab -d name [-e etype] [kvno | all | old] 6984764: kerberos fails if service side keytab is generated using JDK ktab

hg: jdk7/tl/jdk: 6997740: ktab entry related test compilation error

2010-11-05 Thread weijun . wang
Changeset: 856843c444a0 Author:weijun Date: 2010-11-06 09:11 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/856843c444a0 6997740: ktab entry related test compilation error Reviewed-by: valeriep ! test/sun/security/krb5/auto/MoreKvno.java !

hg: jdk7/tl/jdk: 6952519: kdc_timeout is not being honoured when using TCP

2010-11-08 Thread weijun . wang
Changeset: e27ad63b0f54 Author:weijun Date: 2010-11-09 08:34 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/e27ad63b0f54 6952519: kdc_timeout is not being honoured when using TCP Reviewed-by: valeriep ! src/share/classes/sun/security/krb5/KrbKdcReq.java +

hg: jdk7/tl/jdk: 6987827: security/util/Resources.java needs improvement

2010-11-11 Thread weijun . wang
Changeset: 4565d120e514 Author:weijun Date: 2010-11-11 15:51 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/4565d120e514 6987827: security/util/Resources.java needs improvement Reviewed-by: valeriep ! src/share/classes/com/sun/security/auth/NTDomainPrincipal.java !

hg: jdk7/tl/jdk: 6960894: Better AS-REQ creation and processing

2010-11-12 Thread weijun . wang
Changeset: 1e7dc87fad95 Author:weijun Date: 2010-11-12 21:33 +0800 URL: http://hg.openjdk.java.net/jdk7/tl/jdk/rev/1e7dc87fad95 6960894: Better AS-REQ creation and processing Reviewed-by: valeriep ! src/share/classes/com/sun/security/auth/module/Krb5LoginModule.java !

Re: Code Review Request 6203816 and 6720456

2010-11-17 Thread Weijun Wang
On 11/18/2010 07:31 AM, Valerie (Yu-Ching) Peng wrote: Hi, Max, Can you please help reviewing the following two regression test fixes? 6203816: Can not run test/java/security/Security/ClassLoaderDeadlock.sh from the command line Webrev: http://cr.openjdk.java.net/~valeriep/6203816/webrev.00/

Re: Code Review Request 6203816 and 6720456

2010-11-18 Thread Weijun Wang
/closed is still not updated. Thanks Max Valerie On 11/17/10 17:00, Weijun Wang wrote: On 11/18/2010 07:31 AM, Valerie (Yu-Ching) Peng wrote: Hi, Max, Can you please help reviewing the following two regression test fixes? 6203816: Can not run test/java/security/Security

  1   2   3   4   5   6   7   8   9   10   >