Home | Contact Us | FAQ | Search & Site Map | Link to Us
Sign In | Join | Other 45 Sites in Network
HomeAnnouncementsWhite Papers
Discussion GroupsFirst AidDatabasesJavaBeansGUIJava 3DVirtual MachineCORBASecurityToolsGeneral
Java DirectoryOpen Source ProjectsSample Book ChaptersUser GroupsWeb Resources
Related Topics
Databases.NETMore Topics ...

Java Forum / General / April 2007

Tip: Looking for answers? Try searching our database.

[signed applet] certification authority

Thread view: 
oliv@linuxmail.org - 01 Apr 2007 19:40 GMT
Hi,
I have a signed applet (signed myself with jarsigner.exe).
It works fine but the users get a warning message before accepting the
applet to execute.
Next step, is to have my certificate trusted by Verisign or other
third party.
Do you know any link to a site that would explain the procedure to
follow in details ?
Which certification authority would you recommend ? the cheapest ?

thanks
Andrew Thompson - 02 Apr 2007 03:09 GMT
...
>I have a signed applet (signed myself with jarsigner.exe).
>It works fine but the users get a warning message before accepting the
>applet to execute.

So is that (fine).

>Next step, is to have my certificate trusted by Verisign or other
>third party.

Note that although the warning message might be slightly
different, the end user will still be warned, and asked to accept,
a fully verified security certificate, before the applet is trusted.

>Do you know any link to a site that would explain the procedure to
>follow in details ?
>Which certification authority would you recommend ? the cheapest ?

Thawte offers a 'FreeMail' certificate.  I have not gone
through the process, but it is supposedly completely
free.

Signature

Andrew Thompson
http://www.athompson.info/andrew/

oliv@linuxmail.org - 02 Apr 2007 14:52 GMT
As to applet, Thawte does not seem free at all to me (200$ / year !!).
http://www.thawte.com/ssl-digital-certificates/code-signing/index.html

None of you have gone through the process of having an applet
authentificated by a third party certifiaction authority (to assure
the integrity and authorship of the code) ?
I am looking for feedback on that process..

thanks
Andrew Thompson - 02 Apr 2007 15:38 GMT
>As to applet, Thawte does not seem free at all to me (200$ / year !!).
>http://www.thawte.com/ssl-digital-certificates/code-signing/index.html

A search on 'thawte freemail' should lead you to a different page
http://www.thawte.com/secure-email/personal-email-certificates/
One person who ..used to poast around these groups got
one of those for code signing, but I almost prefer the self-signed
certificate to one that says (AFAIR) 'Thawte Freemail..' and no
name of the actual code signer.

>None of you have gone through the process of having an applet
>authentificated by a third party certifiaction authority (to assure
>the integrity and authorship of the code) ?

Authorites like Thawte never glance at code.
They verify *you*.

>I am looking for feedback on that process..

Sorry.  I have no experience in that process, I
have always used self-signed certificates.

What does the code do, that requires extra
privileges?  (e.g. File access, network access..).

Signature

Andrew Thompson
http://www.athompson.info/andrew/



Free Magazines

Get these publications absolutely FREE for up to 12 months. There are no hidden fees and no obligation. Simply choose a title, complete the application form and submit it. Read more ...

Oracle MagazineNetwork ComputingComputer WorldBio-IT WorldeWeekInformation WeekInfosecurity
 
Sign In
Join
My Latest Posts
My Monitored Threads
My Blog
My Photo Gallery
My Profile
My Homepage

Start New Thread
Enable EMail Alerts
Rate this Thread



©2009 Advenet LLC   Privacy Policy - Terms of Use
This website includes both content owned or controlled by Advenet as well as content owned or controlled by third parties.