Some Eclipse Foundation services are deprecated, or will be soon. Please ensure you've read this important communication.

Bug 345656

Summary: Disambiguate SslContextFactory#validateCerts property
Product: [RT] Jetty Reporter: Chad La Joie <clajoie>
Component: serverAssignee: Michael Gorovoy <mgorovoy>
Status: RESOLVED FIXED QA Contact:
Severity: normal    
Priority: P3 CC: gregw, jetty-inbox, mgorovoy
Version: unspecified   
Target Milestone: 7.2.x   
Hardware: PC   
OS: Mac OS X - Carbon (unsup.)   
Whiteboard:

Description Chad La Joie CLA 2011-05-12 16:08:06 EDT
Build Identifier: 7.3.1

In the SslContextFactory, the "validateCerts" method controls the validation of the end-entity certificate by the user of that certificate and the validation of received certificates.  If the end-entity certificate validation is not done away with (see bug #345655), this property should be split in to two different ones.  As it stands right now, as best as I can tell, it would be impossible to have a self-signed end-entity certificate and to use client-cert auth.


Reproducible: Always
Comment 1 Michael Gorovoy CLA 2011-05-13 17:36:45 EDT
Committed r3141.