IBM Support

IV36144: UNEXPECTED JNLPEXCEPTION WHILE LAUNCHING JAVA WEBSTART APPLICATI ON

Subscribe

You can track all active APARs for this component.

 

APAR status

  • Closed as program error.

Error description

  • Error Message: NLPException<OSB>category: Security Error :
    Exception: null : LaunchDesc:
    .
    Stack Trace: at
    com.sun.javaws.security.JNLPSignedResourcesHelper.checkSignedRes
    ourcesHelper(Unknown Source)
     at
    com.sun.javaws.security.JNLPSignedResourcesHelper.checkSignedRes
    ources(Unknown Source)
     at com.sun.javaws.Launcher.prepareResources(Unknown Source)
     at com.sun.javaws.Launcher.prepareAllResources(Unknown Source)
     at com.sun.javaws.Launcher.prepareToLaunch(Unknown Source)
     at com.sun.javaws.Launcher.prepareToLaunch(Unknown Source)
     at com.sun.javaws.Launcher.launch(Unknown Source)
     at com.sun.javaws.Main.launchApp(Unknown Source)
     at com.sun.javaws.Main.continueInSecureThread(Unknown Source)
     at com.sun.javaws.Main.access$000(Unknown Source)
     at com.sun.javaws.Main$1.run(Unknown Source)
     at java.lang.Thread.run(Thread.java:780)
    .
    When a certificate in the CertPath is revoked, the expected
    exception is java.security.cert.CertPathValidatorException.
    Instead a JNLPException is thrown.
    
    The incorrect exception was thrown only with JDK 7 SR3.
    

Local fix

  • No Workaround.
    

Problem summary

  • Although all the application jars are signed, an internal flag
    was not set which results in the exception. The reason was that
    certification validation was done to access the CodeSource
    instead of doing signer verification of the CodeSource.
    

Problem conclusion

  • This defect will be fixed in:
    7.0.0 SR4
    .
    The JDK has been updated to verify the signer instead of the
    certificate for accessing the CodeSource.
    

Temporary fix

Comments

APAR Information

  • APAR number

    IV36144

  • Reported component name

    JAVA CLASS LIBS

  • Reported component ID

    620700130

  • Reported release

    700

  • Status

    CLOSED PER

  • PE

    NoPE

  • HIPER

    NoHIPER

  • Special Attention

    NoSpecatt

  • Submitted date

    2013-02-01

  • Closed date

    2013-03-26

  • Last modified date

    2013-03-27

  • APAR is sysrouted FROM one or more of the following:

  • APAR is sysrouted TO one or more of the following:

Fix information

  • Fixed component name

    JAVA CLASS LIBS

  • Fixed component ID

    620700130

Applicable component levels

  • R700 PSY

       UP

[{"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSNVBF","label":"Runtimes for Java Technology"},"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"7.0","Line of Business":{"code":"LOB36","label":"IBM Automation"}}]

Document Information

Modified date:
22 February 2022