Workaround for 3d Party SSL Providers no longer supported in J2SE 1.4.1

Hi all,
We ran into the new 1.4 property wherein the SSL & TLS implementations cannot be loaded from a 3d party provider any longer and found the corresponding notes in the SSL Overview. We need to provide IAIK JSSE support for a customer (our app is both client and server).
I am wondering several things:
1) has anyone come up with a workaround? Something the lines of writing a non-Sun context class and doing the load oneself?
2) is Sun going to provide some workaround to this?
and more technically and specifically
3) is there a JSSE implementation guide link that covers how dynamically loaded socket factories get their secure random as well as trust managers and key stores? IAIK makes reference to getting these from system properties and I was wondering if this is the "correct" way to get them (I assume that it is) and if so where the documentation for this might be (specifically, what are the property names that one puts into the system properties)?
thanks,
Christopher Preston
[email protected]

IAIK has an update release that should load with JDK1.4. If this is not a solution, in my opinion there is no way to load a non JDK1.4 / JCE1.2.1 compliant provider (except you alter the VM and some runtime classes). I had a deep look at the implementation of JCE1.2.1 some time ago and I can say that the implementation is waterproof against other providers, in special the fact of providers permitting greater keylength than the defined values in the property/policy files.

Similar Messages

  • No MDB for third party JMS

    Just when I getting to like oc4j I ran into this.
    It is a beta document for 904 oc4j.
    Oracle9iAS Containers for J2EE
    Services Guide
    Release 2 (9.0.4)
    Part No. B10326-01
    April 2003
    Beta Draft March 21, 2003 11:59 am
    Third-Party JMS Providers
    This section discusses the following third-party JMS providers and how they
    integrate with OC4J using the resource provider interface:
    ¦WebSphere MQ
    ¦SonicMQ
    ¦SwiftMQ
    Here are the operations that the resource provider interface supports:
    ¦Look up queue and topic with
    java:comp/resource/providerName/resourceName
    ¦Send a message in EJB
    ¦Receive a message synchronously in EJB
    The context-scanning resource provider class is a generic resource provider class
    that is shipped with OCJ for use with third-party message providers.
    Note: Oracle supports only single-phase commit semantics for
    resource providers other than OJMS.
    Note: OC4J 9.0.4 does not offer MDB support for third-party JMS
    providers.
    Note: For the OC4J 9.0.4 implementation, MDBs are integrated
    with OC4J JMS and OJMS.
    Well I need MDB capability with Mqseries, so it looks like
    I am going to have to abandon ship with oc4j, and go with
    a J2EE server which supports MDB and JMS the way it was intended to, and not only work with the Vendors JMS implementation. I checked this 10.0.4 preview and it is
    the same way.
    I would be tickled if someone could tell me this is not
    the case, but I'm not expecting any answer that would
    make an MDB work with Mqseries.

    10.1.3 Developer Preview supports MQServies.
    You can download the software at http://www.oracle.com/technology/tech/java/oc4j/1013/index.html
    Look at the howto at http://www.oracle.com/technology/tech/java/oc4j/1013/howtos/how-to-mq-jms/doc/how-to-mq-jms.html
    http://www.oracle.com/technology/tech/java/oc4j/1013/howtos/how-to-mq-jms/how-to-mq-jms.zip
    The earlier releases support MQ Series but not in a transactional way.
    -Debu

  • Does OSB10gr3 support third-party security providers?

    Does OSB 10gr3 support third-party security providers and third-party token handlers ?
    If so what are they?
    Edited by: dbr6 on Jun 26, 2009 6:01 PM

    OSB will work with any security provider that is designed as per http://download.oracle.com/docs/cd/E12840_01/wls/docs103/dvspisec/index.html. OSB completely relies on Weblogic security framework and doesn't do any official certification for third-party security providers.
    Cheers
    Manoj

  • Best workaround for editing long AVCHD clips in CS6?

    Hi there, I've recently switched to CS6 and have run into incredibly long render times using native AVCHD clips (13 hours to encode a 30 minute m2v).  After reading many posts it seems the issue I am running into is a known bug.  So, my question is: is there a good workaround for this issue?
    It sounds like this issue is only on long clips.  Is it possible to automatically split the .mts files using another program (virtualDub?) prior to importing?
    If transcoding from the native format is required (until the fix) what would be the best method using Windows 7 64bit?  I have heard Avid's DNxHD is a good lossy codec, but I hate to do this if there is an accepted workflow I should learn instead.
    Thanks for any advice!
    -Stephen

    One of these message threads may have some help
    CS6 Bug AVCHD http://forums.adobe.com/thread/1004369?tstart=0
    -and http://forums.adobe.com/thread/1004369?start=0
    -and LOCK the media http://forums.adobe.com/thread/1077245

  • My bank (Chase) and my wife's payroll provider (ADP) say I can longer pull our statements because of incompatibilities between Adobe Reader and Safari. The Apple site says it is not responsible for for 3rd party software. Adobe says go back to Safari 5.0.

    My bank (Chase) and my wife's payroll provider (ADP) say I can no longer pull our statements because of incompatibilities between Adobe Reader and Safari. The Apple site says it is not responsible for for 3rd party software. Adobe says go back to Safari 5.0. Apple dosen't let me download Safari 5.0; so what do I do. The bank had me download Chrome, and I can now download my statements. but what a pain. Any suggestios?

    Back up all data.
    Quit Safari. In the Finder, select Go ▹ Go to Folder... from the menu bar, or press the key combination shift-command-G. Copy the line of text below into the box that opens, and press return:
    /Library/Internet Plug-ins
    From the folder that opens, remove any items that have the letters “PDF” in the name. You may be prompted for your login password. Then launch Safari and test.
    If you still have the issue, repeat with this line:
    ~/Library/Internet Plug-ins
    If you don’t like the results of this procedure, restore the items from the backup you made before you started. Relaunch Safari again.

  • [svn] 4910: Implementing workaround for history manager rendering issue ( Firefox/Mac) caused by a long standing player bug.

    Revision: 4910
    Author: [email protected]
    Date: 2009-02-10 11:51:58 -0800 (Tue, 10 Feb 2009)
    Log Message:
    Implementing workaround for history manager rendering issue (Firefox/Mac) caused by a long standing player bug.
    Bugs: SDK-17020.
    QE Notes: None
    Doc Notes: None
    Reviewer: Alex
    Tests: DeepLinking
    Ticket Links:
    http://bugs.adobe.com/jira/browse/SDK-17020
    Modified Paths:
    flex/sdk/branches/3.x/frameworks/projects/framework/src/mx/managers/BrowserManagerImpl.as
    flex/sdk/branches/3.x/templates/html-templates/client-side-detection-with-history/history /history.js
    flex/sdk/branches/3.x/templates/html-templates/express-installation-with-history/history/ history.js
    flex/sdk/branches/3.x/templates/html-templates/no-player-detection-with-history/history/h istory.js

  • How Do You Generate a 2048bit CSR for a Third Party SSL Certificate for LMS 4.0.1?

    Our site requires Third Party SSL certificates to be installed on our servers.  We have an agreement with inCommon. I have to supply a CSR in order to obtain the SSL certificate.
    My installation is on a Windows 2008 server and I had the self-signed CSR already but it is only 1024 bits.  Is there someplace in the GUI or OS where I can change the encryption?

    This is a shot in the dark, but since CiscoWorks is using (I believe) Tomcat as the web server, could you run keytool to generate the CSR?
    http://help.godaddy.com/article/5276
    You could also use an online CSR gererator such as:
    http://www.gogetssl.com/eng/support/online_csr_generator/
    The key (pun intended) is having the private key on your server so that when you get the signed certificate and install it (using sslutil) it will be usable.
    Hope this helps.

  • Unsigned ssl certificates no longer work

    Since the patch a few days ago SSL certs no longer work if they are unsigned, like for a development server, on Safari for Windows.
    There's no error or option to accept the certificate, and there is nothing in options to allow certs that are not "safe".
    Normal SSL sites with signed certs work as expected. My dev server works as expected with Firefox and IE.
    I am honestly trying to support mac/safari users but this bug makes it very difficult to test. I'm definitely not purchasing a verisign cert for my development server.
    /sigh
    I'll keep looking for next update. I've reported the bug to apple. If anyone knows a workaround please let me know. I searched the apple hives in the registry but there's nothing there.
    Safari 3.0.3(522.15.5)
    -Neil

    I have no idea if the patch did this to me, but.......you might want to check...
    The file /System/Library/Keychains/X509Anchors was EMPTY after I did some kind of update.
    Well, Luckily I back up my system. And I had an old copy of my file. When I restored this file, SSL started working in Safari again. You can see if X509Anchors has daya by opening and running:
    /Applications/Utility/Keychain Access
    See if you can find a way to restore this file (if yours is empty). If you can't, I'll email you mine.
    Feel free to send me an email: medtrac64 @ yahoo.com

  • I have just bought a new Imac and it will not load my copy of FCE 3.5 as it says "PowerPC applications are no longer supported". So how do I get to use the version of FCE I am used to and have paid for ?

    I have just bought a new Imac and it will not load my copy of FCE 3.5 as it says "PowerPC applications are no longer supported". So how do I get to use the version of FCE I am used to and have paid for ?

    I do not have any experience with Final Cut, but if you have existing projects that you MUST access; then you are in need of a solution on your new iMac in Mountain Lion!
    Unfortunately you got caught up in the minor miracle of Rosetta.  Originally licensed by Apple when it migrated from the PowerPC CPU platform that it had used from the mid-1990's until the Intel CPU platform in 2006, Rosetta allowed Mac users to continue to use their library of PPC software transparently in emulation.
    However, Apple's license to continue to use this technology expired with new releases of OS X commencing with Lion (and now Mountain Lion).  While educational efforts have been made over the last 6 years, the fact is that Rosetta was SO successful that many users were caught unaware UNTIL they upgraded to Lion or Mountain Lion.
    Workarounds:
    1.  Purchase a used Mac that will run Snow Leopard (with the optional Rosetta installed) and continue to run FCE on that Mac (you can actually use Screen Sharing with a "headless" used Snow Leopard Mac Mini and use the 27" screen from your iMac to view and work FCE in the Mac Mini environment);
    2.  Upgrade to an Intel compatible version of FCE and hope it converts your existing projects to its newer format correctly.  There is much debate that the newer version of Final Cut are eliminating many needed features; for example Final Cut Pro X vs. Final Cut Pro 6 -- many users are staying with version 6;
    3.  Install Snow Leopard (with Rosetta) into Parallels and then install FCE in the Snow Leopard environment:
                                  [click on image to enlarge]
    Full Snow Leopard installation instructions here:
    http://forums.macrumors.com/showthread.php?t=1365439
    NOTE: STEP ONE of the instructions must currently be completed on a Snow Leopard or Lion Mac and the resulting modified Snow Leopard.cdr install file can then be moved over to your Mountain Lion Mac for completion of the remaining steps.
    NOTE 2:  Computer games with complex, 3D or fast motion graphics make not work well or at all in virtualization.

  • Has anyone come up with new workarounds for Logic routing bugs?

    There have been many threads regarding what seem to be a set of similar bugs. These inlude an audio intrument not sounding after a while, or a channel of automation not being read; and the problem is easily fixed by closing and re-opening the song. That would be a fine workaround except that some songs take a long time to load. I used to have these problems occasionally, but recently they have become so common as to be almost constant. That's bad news, but it also is potentially good news since it means that something in my system has an influence on these bugs. I haven't found a thread in which anyone isolated a factor that helps or hurts, but it's hard to imagine all the keywords for this set of problems, so maybe I missed an idea.
    Also a new similar bug has started appearing in my system. When I add a bus send, once in a while either some or all audio channels will go silent, even though the graphic indicators indicate that they should be heard. The silent channels might or might not include the one with the new bus send. Remove the bus send and the sound comes back.
    It seems as though changes in routing have binding problems.
    Thanks for any ideas!

    Absolutely no ideas on workarounds. I have the exact same issues.
    Most of the time restarting the computer and session will cure them, but there have been projects where no matter what I do, the faders will not follow the automation data and EXS24 instruments cut out at the same exact time in the arrangement. This occurs even with as few as 6 EXS24 instruments open when on some projects I have up to about 85 open and 30 streaming at the same before I get a CoreAudio error.
    Terrible...terrible.
    Any word on whether or not 7.2 addresses this issues?

  • Hi i  insttalled the free trial 3O days MacScan on OsX10.5 is it normal that for full scaning it takes so long time more even than one day?! on the other hand this application hasn't any uninstaller on image disc ,so how can i uninstal it from my hard?

    Hi i  insttalled the free trial 3O days MacScan on OsX10.5 is it normal that for full scaning it takes so long time more even than one day?! on the other hand this application hasn't any uninstaller on image disc ,so how can i uninstal it from my hard?Thanks

    Get rid of the tracking cookies. They are used to profile and track your browsing history. While they are privacy invading, by calling them spyware, MacScan is being a little dramatic in trying to sell you its crap. And in the future, for whatever browser you use, don't allow third-party cookies.
    To prevent tracking, get Ghostery. In addition to having Ghostery and forbidding third-party cookies, I clear out all cookies from one browsing session to another. If you always do that, you won't have any tracking cookies to worry about, so you won't need MacScan to find them for you. Btw, MacScan finds the tracking cookies in the first few minutes of scanning; if you want to use it for that, then that's all the time you need to run it for. But, as I said, you won't have any tracking cookies around if you just remove all cookies and don't allow third-party cookies. As soon as you visit a site that needs them, you'll just get new ones. No problem.
    Read all about cookies here.
    http://en.wikipedia.org/wiki/HTTP_cookie

  • Workaround for inability to scan on USB 3.0 port

    I've got a late 2012 era Mac Mini (specifications here) that I'm trying to set up as a printing and scanner server for my Brother MFC-7340.
    Long story short, I have discovered that scanning does not work when the MFC-7340 is plugged in to a USB 3.0 port. In this case, scanimage returns the following error:
    scanimage: open of device brother3:bus4;dev2 failed: Invalid argument
    and does not scan. This occurs on both my Mac Mini and my laptop (both running Arch) when plugged into a USB 3.0 port. When I plug the scanner in to a USB 2.0 port on my laptop, however, scanimage is successful.
    I have found some mentions of this as a bug here and here, though unfortunately there is no mention of a solution beyond plugging the device in to a USB 2.0 port. However, this is not an option for my Mac Mini since all of its ports are USB 3.0.
    As such, I am wondering whether there is any way to force a USB 3.0 port to function as a USB 2.0 port? Failing that, would anyone have any ideas of other possible workarounds? Note I have attempted all the possible fixes/workarounds listed in the first answer to this question on askubuntu that I was able to -- I didn't set "XHCI Pre-Boot mode", for example, since AFAIK Apple provides no mechanism for changing BIOS/UEFI options.
    As a final note, I am fairly certain that I am not facing any fundamental hardware limitation that would prevent this setup, since I have been able to use the same scanner with the Mac Mini from inside OSX.

    How would I test this out? Would blacklisting xhci-hcd cause ehci-hcd to be loaded automatically as its replacement?
    EDIT: I blacklisted xhci-hcd, updated my initramfs and rebooted. xhci_hcd was gone from lsmod, and ehci_hcd had been loaded, so that all seems to have worked. However, now when I run scanimage, for example, I get
    # scanimage > out.pnm
    scanimage: no SANE devices found
    and lsusb can no longer see the scanner (and for that matter can't see an external HDD I have plugged in either).
    Last edited by 12qu (2014-07-27 10:37:11)

  • WLC Virtual Interface config for a public SSL cert for Web Authentication

    I'm trying to get a cert loaded on my 5508 WLC running 7.6.130.0 so when a Web-Auth users tries to authenticate they don't get the SSL cert error.
    In the document "Generate CSR for Third−Party Certificates and
    Download Chained Certificates to the WLC"
    Document ID: 109597 it states the following
    "Note: It is important that you provide the correct Common Name. Ensure that the host name that is
    used to create the certificate (Common Name) matches the Domain Name System (DNS) host name
    entry for the virtual interface IP on the WLC and that the name exists in the DNS as well. Also, after
    you make the change to the VIP interface, you must reboot the system in order for this change to take
    effect.
    Here are my questions.
    1. I have always had 1.1.1.1 as the address of the Virtual interface, should that change or can I leave it as 1.1.1.1?
    2. In the "DNS Host Name" Field do I simply put the domain or the FQDN?  Example. Company.com or hostname.company.com

    Hi,
    1) You can change that if you want. Normally it is non-Public and non-routable in your network.
    2) Put the Host name for which you are going to give in your company DNS server where that Host name would be mapped to the Virtual ip address.
    Regards
    Dhiresh
    ** Please rate helpful posts**

  • Generate CSR for Third-Party Certificates

    Hi All,
    i have an issue when i tried to Generate CSR for Third-Party Certificates,
    i follow step by step in the document of cisco until this step:
    3.
    Now that your CSR is ready, copy and paste the CSR information into any CA enrollment tool.
    In order to copy and paste the information into the enrollment form, open the file in a text editor that
    does not add extra characters. Cisco recommends that you use Microsoft Notepad or UNIX vi. Refer
    to the website of the third−party CA for more information on how to submit the CSR through the
    enrollment tool.
    After you submit the CSR to the third−party CA, the third−party CA digitally signs the certificate and
    sends back the signed certificate via e−mail.
    4.
    Copy the signed certificate information that you receive back from the CA into a file.
    This example names the file CA.pem.
    my issue is where i sould copy and paste the CSR information into any CA enrollment tool. i just have done create mykey.pem and myreq.pem in my folder OpenSSL\bin
    Please help and Thanks you.
    Regards,
    Jasa

    you have to do more steps using openssl.
    before you obtain the third−part certificate, you have to copy that on a notepad text, and you have to obtain an intermediate and root certificate from the company that gives you the certificate.
    Then you have to copy and paste on a notepad or gedit:
    SSL (the certificate that they give you)
    Intermediate (the certificate that you obtain from the company that gives you the certificate)
    Root (the certificate that you obtain from the company that gives you the certificate)
    name the text file like: allcerts.pem
    then... you have to run this commands:
    C:\OpenSSL\bin>openssl pkcs12 -export -in allcerts.pem -inkey mykey.pem -out All-certs.p12 -clcerts -passin pass:yourpassword -passout pass:yourpassowrd
    C:\OpenSSL\bin>openssl pkcs12 -in All-certs.p12 -out finalcert.pem -passin pass:yourpassword -passout pass:yourpassword
    Then you are going to have a file named: finalcert.pem, thats the one you have to update to the WLC. please note that on those lines "yourpassword" is the password you use when you create the certificate and its going to be the same that you have to use for upload to WLC.
    Note that you have to use openssl version 0.9.8 because its the only version thats WLC support
    If you have doubts please contact me.
    Have fun!

  • ATP check CRM R/3 for Third Party items

    CRM .0 does not support an ATP check for Third Party items. This
    is axplained in several notes and we also find it in practice in
    our system. Actually an ATP check does also not happen in R/3,
    if you create the order in R/3, but it takes the delivery lead
    time, from the material or the info record, into account for the
    confirmation date.
    ATP check from CRM to R/3 is triggered by the requirements class
    that is determined in R/3 from the item category. So in case
    during an ATP chekc from CRM in R/3 no requirements class is
    found for the item category, as this is the case for the third
    party item category the system does no futher action and does
    not take the delivery lead time into account.
    This is standard system behaviour.
    We are setting up a webshop where the above mentioned could
    result in a partial confirmed order during order simulate. The
    customer will not be able to view the confirmed date before
    actually saving the order.
    My question is if anybody ever tried to find a workaround or
    solution for this missing functionality.
    Best regards,
    Pascal.

    Hi Pascal,
    Middleware setting is only to activate the ATP call from CRM to R/3. It has nothing to do with the pop-ups you are getting. I don't remember on top of my head how to eliminate this situation. I think when you call ATP, the system is validating the partner functions. Check partner determination profile assigned to the transaction type. I believe you need to make some changes to the partner profile. Are you getting these pop-ups only for a particular transaction type?
    <b>Do not forget to reward if it helps,</b>
    Regards,
    Paul Kondaveeti

Maybe you are looking for

  • I have 2 ipods on one id and want to change to separate ids

    I have 2 ipods on one id (mine and my sons) and want to change to separate ids as fed up of listening to his music can this be done?

  • Looking for Sendmail PL/SQL Package

    Hi All, I am looking for a way to call Sendmail directly from a PL/SQL Procedure. Can someone point me in a direction where I can find some PL/SQL or Pro*C Code that could do this? Thanks, Scott Walton null

  • PXI-8195 won't boot after installing LV RT 7.1.1

    Dear all, I just installed LV RT 7.1.1 on my RT Target. Unfortunately after doing so I am no longer able to boot the Target. It just stops after BIOS POST with a blinking cursor in the first line on the connected screen. Changing to SaveMode in BIOS

  • Color changes after update

    I have just upgraded to 10.4.10 this morning, Some of my Aperture library files have now taken on a "magenta hue", especially noticeable in the neutral area's. The files are Nikon D200.nef images. I have had made no other recent changes or upgrades t

  • Am I able to download iMovie on a computer that's not a Mac computer

    I am trying to see if i can upload iMovie to my computer but my computer isnt a mac and im wondering if i am able to still download it?