This Bugzilla instance is a read-only archive of historic NetBeans bug reports. To report a bug in NetBeans please follow the project's instructions for reporting issues.
Summary: | Signed, but untrusted modules (Jira dependencies) on Certified plugins UC | ||
---|---|---|---|
Product: | updatecenters | Reporter: | Tomas Danek <musilt2> |
Component: | Stable | Assignee: | Jiri Rechtacek <jrechtacek> |
Status: | VERIFIED FIXED | ||
Severity: | normal | CC: | anebuzelsky, jrechtacek, mmirilovic, pgebauer, pjiricka, tstupka |
Priority: | P1 | ||
Version: | 7.1 | ||
Hardware: | All | ||
OS: | All | ||
Issue Type: | DEFECT | Exception Reporter: |
Description
Tomas Danek
2011-11-23 12:45:28 UTC
*** This bug has been marked as a duplicate of bug 202756 *** yes, it's the same problem as in beta (report for beta was wrong - it's about "unsigned", but should be about "untrusted" as well) . WONTFIX from duplicate won't solve this issue, better idea is probably adding certificate of mentioned modules to keystore. Jirko, please have a look at how JAR signatures are processed in AU client. Is it different from how NBM signatures are processed? I have discovered the way how jars can be signed via jarsigner however javax-activation.jar can't be signed because of following issue: Signing module : NBMs/javax-activation.jar jarsigner: unable to sign jar: java.util.zip.ZipException: duplicate entry: META-INF/LICENSE.txt Error - cannot sign module NBMs/javax-activation.jar I have refreshed 71 certified AUC. The following jars are reported as untrusted even though they have been signed: Mylyn Commons Soap org.eclipse.mylyn.monitor.ui.dummy The file javax.activation is reported as untrusted as well but this report is correct because the file javax.activation cannot be signed (please see my comment #4) Any ideas what to try next? (In reply to comment #3) > Jirko, please have a look at how JAR signatures are processed in AU client. Is > it different from how NBM signatures are processed? There is a same code in AU client as NB6.0 but surroundings are changing. This problem appeared since AU can install OSGi bundles. I find out three place we have to change/fix: 1) AU client has to change evaluating certificates which comes from Jar/NBM (my task, will be fixed tomorrow in trunk) 2) javax.actication has to avoid duplicate entries in the jar (Tomas Stupka's task) 3) needed to sign all jars incl. javax.actiovation after task above (Petr Gebauer's task) > 2) javax.actication has to avoid duplicate entries in the jar (Tomas Stupka's
> task)
caused by merging two jar files into one osgi bundle. had to take care that the license and notice files from both get a distinct name.
pushed to core-main #ec19d339118e
(In reply to comment #7) > > 2) javax.actication has to avoid duplicate entries in the jar (Tomas Stupka's > > task) integrated into release71 #bf24c1592459 Changes in AU client applied in trunk - http://hg.netbeans.org/core-main/rev/09c37ad5e7a2 fixed in release71: http://hg.netbeans.org/releases/rev/eb1b465e4e5c Integrated into 'releases' Changeset: http://hg.netbeans.org/releases/rev/bf24c1592459 User: Tomas Stupka <tstupka@netbeans.org> Log: issue #205476 - Signed, but untrusted modules (Jira dependencies) on Certified plugins UC integrating #ec19d339118e from trunk Verified in latest RC1 build. Tomas, could you confirm too? Product Version = NetBeans IDE 7.1 RC1 (Build 201111242103) (#0845e53258a4) Operating System = Linux version 3.0.0-13-generic running on amd64 Java; VM; Vendor = 1.6.0_20; Java HotSpot(TM) 64-Bit Server VM 16.3-b01; Sun Microsystems Inc. Runtime = Java(TM) SE Runtime Environment 1.6.0_20-b02 Java Home = /usr/local/share/java/jdk1.6.0_20/jre System Locale; Encoding = en (nb); UTF-8 yes, works for me fine now as well. Product Version: NetBeans IDE 7.1 RC1 (Build 201111242103) Java: 1.6.0_29; Java HotSpot(TM) 64-Bit Server VM 20.4-b02-402 System: Mac OS X version 10.7.2 running on x86_64; MacRoman; en_US (nb) User directory: /Users/tomas/.netbeans/7.1rc1 Cache directory: /Users/tomas/.netbeans/7.1rc1/var/cache Integrated into 'main-golden' Changeset: http://hg.netbeans.org/main-golden/rev/ec19d339118e User: Tomas Stupka <tstupka@netbeans.org> Log: issue #205476 - Signed, but untrusted modules (Jira dependencies) on Certified plugins UC Integrated into 'main-golden' Changeset: http://hg.netbeans.org/main-golden/rev/09c37ad5e7a2 User: Jiri Rechtacek <jrechtacek@netbeans.org> Log: #205476: Signed, but untrusted modules (Jira dependencies) on Certified plugins UC |