JCE/JWS Conflicting Signature Requirements

I'm trying to use a JCE cryptography provider in a Java Web Start application, and I'm running into a conflict with JAR signatures:
Using a plugin JCE cryptography provider requires a JAR signed by a certificate chain rooted at Sun's self-signed JCE certificate.
Java Web Start (JWS), on the other hand (if you want full client-side permissions), requires that every JAR be signed by exactly one certificate, and that the certificate be root-trusted according to the cert library that ships with Java (Verisign, etc.).
Unfortunately, as far as I can tell, this means that either:
* JCE's requirement for signature by Sun's JCE chain needs to be waived, or
* I have to load the classes for JCE outside of JWS's resource-loading mechanisms.
Has anyone else faced this? Did you find a solution? Did you just have to load the JCE crypto provider classes outside of Java Web Start?
Bonus question: what is the motivation for requiring exactly one signature (as opposed to two, which is still validatable in my experience) on a JAR file in Java Web Start?

dear bill & all,
my JWS application also employs bouncycastle as the JCE provider. although i can make the application load successfully by specifiying an extension for the JCE resource in the master jnlp file, i still get the warning message returned from JWS' security manager saying the bouncycastle's signature cannot be verified and it recommends the user NOT to install and run the code. The following is the exact message that i got from JWS:
"This library is requesting unrestricted access to your local machine and network.
Do you want to install and run: Versitech e-Form Filler v2.0
Signed and distributed by: The Legion of the Bouncy Castle
Warning: Failed to verify the authenticity of this certificate. No assertions can be made of the origin or validity of the code.
It is highly recommended not to install and run this code"
this is because the bouncycastle provider is signed by a codesigning cert that is issued by SUN whose root CA is not included in the default CA list of JWS.
although one can always ignore such message and continue to launch the application, this is not acceptable by my client who requires strict error/warning-free installation.
does anyone has any clue to solve this problem and make JCE and JWS a true integration?
--matchy                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       

Similar Messages

  • Need to Install Safari 6.0.2 on a white Intel core duo iMac. Had to throw out 6.0.3 because of conflict with required software. Downloaded wrong version that was for Mountain lion (I am running 10.7.5). It installs but won't open.

    Need to Install Safari 6.0.2 on a white Intel core duo iMac. Had to throw out 6.0.3 because of conflict with required software. Downloaded wrong version that was for Mountain lion (I am running 10.7.5). It installs but won't open, says it is for Mountian Lion.
    Of course I can't throw it away since I get a message it's part of the sytem. I can show package contents and throw those away, but evidently not a good idea!!

    Need to Install Safari 6.0.2 on a white Intel core duo iMac. Had to throw out 6.0.3 because of conflict with required software. Downloaded wrong version that was for Mountain lion (I am running 10.7.5). It installs but won't open, says it is for Mountian Lion.
    Of course I can't throw it away since I get a message it's part of the sytem. I can show package contents and throw those away, but evidently not a good idea!!

  • Allow me to dismiss / kill "Signature requires validating" banner

    With monitors more squat than ever, why is Acrobat 9 using bigger icons and banners at the top?  Pretty soon there will be no space for the actual document.
    Well, here's one thing to fix.  When I open a document with a questionable digital signature, I get a blue band almost half an inch high, across the whole top of the display, warning me of this.  Fine.. but I can't get rid of the banner!  I've looked through every Preferences setting and searched the web.  Stuff like this is maddening.
    FEATURE REQUEST ==>  Allow the user to dismiss the "Signature requires validation" warning.
    Sheesh..,

    I finally discover that clicking on the yellow "alert" icon at the left end of the bar will dismiss it.  Maybe that's intuitive to someone.  Thanks to the Adobe staff and all others who took the time to explain this.

  • Info for Signature Require UPS delivery

    This is for those of you who won't be around when your phone is scheduled for delivery.
    I just spoke to a CSR rep for UPS - which took awhile, everytime I've tried to call in the automated voice says that they can't take my call at the moment and to call back later. I finally got through and this is what the CSR told me.
    1) For those who live in apartment complexes - UPS can deliver your package to your complex manager or secretary, as long as they are physically there and able to sign for it.
    2) Your neighbors can sign for the package as well (whether you live in an apartment or house) but it's somewhat discouraged unless you know your neighbor very well. Use your common sense.
    3) If none of the above work for you, you will have to wait until the driver leaves you an infonotice - the little gold and brown form stuck to your door. Once you receive it, call UPS ASAP. They can then arrange for you to pick up your package the same day or possibly have the driver redeliver - usually, the driver won't be able to redeliver though.
    It was made very clear that they driver will NOT be able to leave the package at your house without a person physically signing for it. I have had drivers do this before, even though it was a signature required package, but the CSR told me that for this particular package the drivers have all been instructed that they must have a person sign - a note or release form will NOT be good enough. Verizon must have been pretty adamant about needing the signature. That being said, there are probably a few drivers out there who would accept a note or forge your signature, but I wouldn't count on it. My problem is that I need the package delivered or picked up on Monday as my schedule for the rest of the week is even worse and I won't be home until after residential deliveries end for the day.
    Anyway, I hope this helped someone - not trying to burst any bubbles, I just wanted to share what I learned so no one has any problems.

    china_cat84 wrote:
    JJMinc wrote:
    Also, if you ordered directly from Apple, you can pre-sign for your shipment online. You'll print out a form and attach it to your door and UPS will collect this form in place of an in-person signature. But while it is correct UPS isn't required to take instructions from Verizon, they WILL NOT leave a package labeled "required signature" without either a physical signature or a pre-authorization notice that they can take with them.
    I ordered mine from Verizon, not Apple, so I can't be 100% sure when I say this, but doesn't Apple ship via FedEx? And I've heard from AT&T people that FedEx didn't always accept the release form for the AT&T iPhones, so they may not always accept it for the Verizon ones either.
    The CSR never said anything about pre-authoization notices...she just said that besides having a neighbor sign or being there yourself, there's nothing you can do until after you get an infonotice. Leaving a note won't hurt, but it's no guarantee. If it was the possibility of YOUR job on the line, would you leave it?
    Mine is coming via UPS and I ordered from Apple. It is possible they are using both couriers, though. And while I'm very familiar with UPS, I don't know too much about FedEx. It may be true they won't accept pre-auth notes. I work in logistics and my UPS preferred account rep did say these pre-auth forms are to be considered a signature by the driver as long as the driver can retrieve it and take it back to the hub. The one downside is, if your phone was damaged during shipment, notes and pre-auth forms mean you can't file a claim. Just a thought.

  • Is a signature required at delivery?

    I received my shipping confirmation email from Verizon just now and it says "signature is required upon delivery".  When I called Verizon on 9/12 to try and change my shipping address I was told by the rep that no one has to be home to sign it.  They would just leave the phone at the door. I would love some confirmation on this since I'm getting conflicting information.  Thank you! 

    It HAS to be signed for as signature is required from someone at the residence at the time of delivery. 

  • Mark areas in a PDF for signatures required

    Dear Acrobat community,
    I would like to mark areas in a PDF where the client is required to place a signature. I am thinking about an colored overlay similar to a yellow text marker.
    I have a license of Acrobat Pro 11 available and I am looking for the right function to use. I have not been able to identify such a feature yet.
    Can you help me out with this topic?
    Best regards

    Hi Trottel ,
    I believe the seventh point in the following document will answer your query.Please go ahead and give it a try .
    http://www.adobe.com/content/dam/Adobe/en/products/acrobat/pdfs/adobe-acrobat-xi-esign-pdf -file-tutorial-ue.pdf
    Feel free to contact us in case you need further assistance.
    Regards
    Sukrit Dhingra

  • Delivery and signature required.

    I a, reading horror stories about deliveries on here and I too am experiencing the same problem! My IPad Air 2 is supposed to be delivered today. They. Will not leave it with a neighbor because the way BB set up the delivery.. I am not home during the name, I. a not schedule a time for the delivery because of the way BB. Set the delivery. I am so lividddd right now. AND TO TOP IT OFF. MY CREDIT CARD WAS CHARGED WEEKS AGO.
    signed, unhappy customer.

    Hello netwrkwoman,
    I have yet to make the leap and buy myself an Apple iPad, but it’s an item I’ve seriously debated buying for some time now.  It’s disappointing to hear of the troubles you’ve run into while waiting for UPS delivery though, and I apologize for any frustration this may be causing.
    Upon review of your order using the email address provided on the forum, it seems your order is requiring a signature for UPS to deliver the purchase. After three unsuccessful attempts, they may ship the item to us so that we may provide you a refund. Because of this, I realize you may wish to modify the shipping address so that your order may be delivered to another who is available to sign for the package. Please know that after 30 minutes of placing the order, we are rarely able to modify an online purchase. As your device is already with UPS, we’d be unable to honor your request to deliver the iPad to another address.
    Having said this, you may have another option available to you. While they do not have this option available for all deliveries, UPS may leave a note on your door requesting you to contact them to arrange a specific delivery date to ensure you’re home to receive the order. If so, I’d suggest doing this to avoid any further missed delivery attempts.
    Best wishes,

  • Valid signature required at bottom. not at top or signature panel.

    Hi Experts,
    I am using Adobe Reader X. When i did validate signature.. green tick mark is coming either top or signature panel side. I required this on exact place of signature. Actually this was working in old versions of adode reader. This feature is not coming on proper place of Adobe reader x. Please provide the solution on this ASAP.
    Thanks
    [email protected]

    Dan:
    The keyword pane used for assigning them to photos cannot be added to the info pane at the window. It's the nature of the beast. You can put in a feature request at http://www.apple.com/feedback/iphoto.html. I've not used it but Keyword Manager might be less obtrusive and work better in the smaller screen of the MBP. You can find it at VersionTracker.com and run it in demo mode.
    TIP: For insurance against the iPhoto database corruption that many users have experienced I recommend making a backup copy of the Library6.iPhoto database file and keep it current. If problems crop up where iPhoto suddenly can't see any photos or thinks there are no photos in the library, replacing the working Library6.iPhoto file with the backup will often get the library back. By keeping it current I mean backup after each import and/or any serious editing or work on books, slideshows, calendars, cards, etc. That insures that if a problem pops up and you do need to replace the database file, you'll retain all those efforts. It doesn't take long to make the backup and it's good insurance.
    I've created an Automator workflow application (requires Tiger), iPhoto dB File Backup, that will copy the selected Library6.iPhoto file from your iPhoto Library folder to the Pictures folder, replacing any previous version of it. It's compatible with iPhoto 08 libraries and Leopard. iPhoto does not have to be closed to run the application, just idle. You can download it at Toad's Cellar. Be sure to read the Read Me pdf file.

  • Remove / Disable the signature requirement on a Form

    This is my first form so this is probably a really easy question.  I would like a user to be able to complete the form and then save it without having to sign it.  Having the signature complicates the process so I would like to remove the requirement all together.  I haven't added any signature fields.  It's just automatically showing up and prompting the user when they try to complete the form.  I've searched on the forum and through XI Pro and I can't find the setting to turn it off.  How can I turn this off?  Thanks!

    Hi Robert,
    It sounds like you are talking about the prompt in Acrobat Reader that advises users to "Click "Sign" to fill out and sign this form. When you are done, you can save a copy by clicking "Done Signing"."  This prompt confuses and annoys a lot of people. You can make it go away by saving your form as Reader Extended. In Acrobat, Save as Other > Reader Extended PDF > Enable More Tools (includes form fill-in & save). Exact terminology varies depending on your version of Acrobat. Be sure to save a copy of the non-extended version of the form for future editing.
    If you have just a few known users you could also ask them to upgrade to Reader XI, I understand it does not display the annoying prompt. Or you could ask them to ignore the prompt, which they can do - it does not effect the use of the form other than causing confusion.
    Hope this helps.
    a 'C' student

  • Two signatures required on a document-one person applies both signatures and approves the document

    Does anyone know how to disallow someone from putting two digital signatures on a document when one signature is for the employee and the other is for the supervisor's approval? We have never allowed digital signatures because someone raised this question because they were able to create a digital signature in their supervisor's name and affix it on the document in the approval space. Is there any way to tell that both signatures were created by the same person?  I only have LiveCycle Designer 9.0 and Adobe Acrobat Pro X.  It seems that there should be some code in the signature details that shows that they were both created at the same source. I've checked the certificates details on multiple names that I created and they were different every time I affixed a signature (even one for my dog) so there was no way that I could see, that we could prove that the signatures were or weren't both affixed by the same person. Until I have a way to stop this from happening, we cannot use digital signatures on our documents. There needs to be a way to trace the signature back to the source.

    There are many ways to generate a digital certificate (digital ID) that can be used to sign a document.  In your post you are describing what are referred to as "self-signed" certificates.  This means that any user can create their own identity (as you have discovered) and sign a document with it.  Acrobat and many other utilities are available that can be used to generate self-signed certificates.  Using self-signed certificates can be useful in a scenario where you have established some level of trust with the signer.  Usually this involves a relationship with the signer where you have explicitly trusted their digital certificate by importing the public key portion of their digital id.  This use of signatures is not suited for non-repudiation, but it does allow you to determine if the document was modified or tampered with after it was signed.
    When you need signatures to also guarantee the identity of the signer, then you must implement some type of Public Key Infrastructure (PKI).  A PKI handles the creation, issuing and revocation of digital certificates (digital ids), typically a user must prove they are who they say they are for the system to generate them a digital certificate.  VeriSign and Entrust are two examples of PKI vendors.  Trust of the signer can then be implicit, you "trust" the issuer (or Certificate Authority (CA)), therefore you trust the signatures generate with certificate that came from the  Certificate Authority.  When a certificate is created by a CA, there is a "certificate chain" so you can determine who (which CA) issued the certificate.
    I hope this helps clear things up a bit.
    Regards
    Steve

  • Make a digital signature required

    I am using Lifecycle Designer, and we are on version 8.  I have looked through the Acrobat 8 PDF bible, and have also been searching the web but cannot figure out a way to do what I want.  I see a lot of scripts, where you can set up a submit button to only work if a text box is filled out, but how do I do that based on a digital signature being unsigned.  I have seen scripts that make the dig. signature mandatory, but even when signing it, the script still thinks it is null.  Another option that would work would be if the submit button was read only, until the digital signature was signed.  We are not using the email submit button or the HTTP submit buttion because we wanted to have the entire PDF returned not just the xml.  Is what I am trying to do possible?   I do not have much experience with java script of formcalc.
    thanks in advance,
    Nat

    I am using Lifecycle Designer, and we are on version 8.  I have looked through the Acrobat 8 PDF bible, and have also been searching the web but cannot figure out a way to do what I want.  I see a lot of scripts, where you can set up a submit button to only work if a text box is filled out, but how do I do that based on a digital signature being unsigned.  I have seen scripts that make the dig. signature mandatory, but even when signing it, the script still thinks it is null.  Another option that would work would be if the submit button was read only, until the digital signature was signed.  We are not using the email submit button or the HTTP submit buttion because we wanted to have the entire PDF returned not just the xml.  Is what I am trying to do possible?   I do not have much experience with java script of formcalc.
    thanks in advance,
    Nat

  • Digital Signature - Requirement to Enter User ID

    Whassup Ya'll-
    We'd like to leverage digital signature in our landscape. However, in order to be Part 11 compliant we will need to have our approvers enter both their user ID and corresponding password. However, as it stands when an approver is prompted for an e-sig, the User ID is already populated.
    Please advise how to customize so the user is forced to enter both fields. I'll make it rain with points.
    Cheers

    Have you tried restarting the touchpad by pressing and holding both the center button and the power button together for around 15 - 20 seconds?
    WyreNut
    I am a Volunteer here, not employed by HP.
    You too can become an HP Expert! Details HERE!
    If my post has helped you, click the Kudos Thumbs up!
    If it solved your issue, Click the "Accept as Solution" button so others can benefit from the question you asked!

  • "valid digital signature" required????

    I am trying to download a poker website that i have been using for years and i now get a message saying "...valid digital signature missing...".  I don't understand.  I would appreciate any help.  Thanks

    Sounds like your security settings for their site are missing - such as might happen when you delete temproary Internet files and cookies.
    Best bet would be to call their support number.
    If you have a secure password... then you can use the "unable to view secure web sites" steps in this document to "reset" secure connections:
    http://h10025.www1.hp.com/ewfrf/wc/document?cc=us&docname=bph07138&dlc=en&lc=en&jumpid=reg_R1002_USE...
    ... an HP employee expressing his own opinion.
    Please post rather than send me a Message. It's good for the community and I might not be able to get back quickly. - Thank you.

  • Signature requirement on forms

    I created a form for my business partners to fill out when they have requests of my team. I and added a drop down and a few radio buttons for ease of use. The problem I'm running in to is that the form is erquiring a signature even though there is no signature field. I read some of the other posts and tried saving as a Reader Extended PDF which fixes the signature problem but then I lose the functionality of my drop down and radio buttons. Is there anyway to keep it a dynamic form but remove the signature prompt?

    TallSea,
    I think you may be talking about the problem discussed here: http://blogs.adobe.com/acrobat/adobe-reader-and-acrobat-11-0-3-update-and-signature-field- detection/
    Is that right?

  • Outlook 2013 SP1 S/MIME signature requires entering password twice

    Since updating to Outlook 2013 SP1, every time I send an S/MIME signed email I'm prompted for the password twice.  Prior to SP1, I was prompted once per email (I have PrivKeyCacheMaxItems=0, as I do want to be prompted for each email). Has anyone else
    experienced this behavior?  Is this a bug in SP1 or is there a configuration change to get the "once per email" behavior back?
    Outlook 2013 (15.0.4569.1503) MSO (15.0.4569.1506) 64-bit.
    Windows 7 Ultimate SP1 w/ all Microsoft Update patches.

    As I remember, we don't need to type any password when we send an S/MIME signed email. Could you help to show the titile of pop-up windows? Better to capture a screenshot and post here.
    By the way, does it happen in a new creating profile. And I've never heard the service pack 1 would be the root of this issue. Remove the SP1 to check if the issue would be gone in your machine if necessary. Thanks.
    Tony Chen

Maybe you are looking for

  • Preference panel corruption?

    I have a small, annoying problem in my system preferences. I just noticed that the speech panel is corrupted in some way, and I wonder if anyone has any tips on how to either reinstall it or to fix it. I can click on it like normal, and it opens up t

  • Error in assigning Tax Group - TAXINJ

    Hi, While posting supplier excise invoice thru J1IEX. I'm getting following error Error in Assigning the Tax group. I'm using TAXINJ tax procedure. Please help. Shall be rewarded. Thanks Nikhil

  • How do I get rid of Avast?

    I downloaded a (free) trial of avast security for iPad.  I deleted the app but it has taken over my screen an has me in a loop to renew. I clear the cookies and the history from Safari an did a hard reboot but to no avail.  How can I get out of it?

  • Cached mode on individual outlook accounts

    Is it possible to have multiple exchange accounts with cached mode individually set off for group mailboxes?

  • Downloading the $9.99 lightroom and photoshop

    I just purchased the $9.99 light room and photoshop monthly and it's making me download Creative Cloud first which is already downloaded. When I click on photoshop or lightroom from the adobe website to download it just pulls up creative clous and ha