Menu

#21 Multiple digests of META-INF/Manifest.xml calculated

open
Defect (15)
1
2009-07-09
2009-07-09
No

When signing a package, the META-INF/Manifest.xml is processed twice, resulting in two (presumably identical) digests being included in the signature.

One of the reference is explicit (META-INF/Manifest.xml) whilst the other is relative ("").

The only side effect of this issue is performance and clarity, as the results is still a valid digital signature.

Discussion


Log in to post a comment.

Want the latest updates on software, tech news, and AI?
Get latest updates about software, tech news, and AI from SourceForge directly in your inbox once a month.