-
Notifications
You must be signed in to change notification settings - Fork 224
8296343: CPVE thrown on missing content-length in OCSP response #1361
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
👋 Welcome back apavlyutkin! A progress list of the required criteria for merging this PR into |
This backport pull request has now been updated with issue from the original commit. |
@apavlyutkin This change now passes all automated pre-integration checks. ℹ️ This project also has non-automated pre-integration requirements. Please see the file CONTRIBUTING.md for details. After integration, the commit message for the final commit will be:
You can use pull request commands such as /summary, /contributor and /issue to adjust it as needed. At the time when this comment was updated there had been 6 new commits pushed to the
Please see this link for an up-to-date comparison between the source branch of this pull request and the As you do not have Committer status in this project an existing Committer must agree to sponsor your change. ➡️ To flag this PR as ready for integration with the above commit message, type |
/integrate |
/sponsor |
@apavlyutkin |
Going to push as commit 32fda32.
Your commit was automatically rebased without conflicts. |
@yan-too @apavlyutkin Pushed as commit 32fda32. 💡 You may see a message that your pull request was closed with unmerged commits. This can be safely ignored. |
Hi @apavlyutkin sun/security/provider/certpath/OCSP/OCSPNoContentLength.java fails due to network errors Please backport this, too! |
|
Dear all. The problem with OCSP responders not returning |
@apavlyutkin what needs to be done, to get this issue back on track? |
I will take a look. Thank you |
@apavlyutkin do you have a new issue or ticket number for me that tackles the OCSP issue? |
@apavlyutkin is there any specific process I should follow? Shall I create a new ticket? |
Philip, sorry for long ping, I repent sincerely. I did not have a time for this because I have changed my employment and now JDK is only a side activity for me. IMHO it would be better if you raise a new ticket for this, but the most important here is to share how you reproduce the issue. If the issue is reproducible for the upstream? |
Hi!
Here is backport of JDK-8296343. The patch fixes CertPathValidatorException taking place if OCSP response does not contain
ContentLength
field.Original patch is applied cleanly.
Verification/regression (amd64/20.04 LTS):
jdk_security
including newly addedtest/jdk/sun/security/provider/certpath/OCSP/OCSPNoContentLength.java
Progress
Issue
Reviewing
Using
git
Checkout this PR locally:
$ git fetch https://git.openjdk.org/jdk17u-dev.git pull/1361/head:pull/1361
$ git checkout pull/1361
Update a local copy of the PR:
$ git checkout pull/1361
$ git pull https://git.openjdk.org/jdk17u-dev.git pull/1361/head
Using Skara CLI tools
Checkout this PR locally:
$ git pr checkout 1361
View PR using the GUI difftool:
$ git pr show -t 1361
Using diff file
Download this PR as a diff file:
https://git.openjdk.org/jdk17u-dev/pull/1361.diff
Webrev
Link to Webrev Comment