Unfulfilled Expectations: Revoked Certificates in JAR Signing
Oracle JarSigner does not check CRLs In April 2020 we became aware of a conceptual security issue in the Java JarSigner. The JarSigner does not check ...
Read MoreOracle JarSigner does not check CRLs In April 2020 we became aware of a conceptual security issue in the Java JarSigner. The JarSigner does not check ...
Read MoreWe recently investigated AppVeyor’s “secure variables” (aka “Encrypt YAML”) feature. We wanted to understand the crypto and algorithms it uses (which is not documen ...
Read MoreDocker Content Trust (DCT) is Docker’s mechanism for code signing. Developers can sign images they create and people using these images can verify if they have b ...
Read MoreVulnerability CVE-2019-19781 in Citrix NetScaler has been a pain for organizations' IT departments for the last two weeks and it still keeps us busy supporting our ...
Read More