Why am I not getting any warnings about my java web start application that is signed with an expired certificate?

Viewed 177

I have a java web start application (I deploy a war to Tomcat, user goes to the website and downloads a jnlp which then can be executed). In my build process the jars are signed using a CA authority signed certificate and as far as I can tell without timestamping. The certificate has recently expired.

Extracting jars from the war file and checking them using jarsigner shows:

jar verified.

Warning: 
This jar contains entries whose signer certificate has expired. 
This jar contains signatures that do not include a timestamp. Without a timestamp, users may not be able to validate this jar after any of the signer certificates expire (as early as 2020-02-24).

It appears that:

  • the users can still launch the java web start applications
  • the build job still runs and is able to sign with the expired certificate
  • deploying a newly built version that has been signed with the expired certificate still works and the app still launches

Now I am wondering what is the impact of that expiry, and should I even bother with renewing the certificate and adding to the keystore?

Update:

Server:

  • Tomcat Version Apache Tomcat/9.0.10
  • JVM Version 1.8.0_181-b13

Client:

  • Java Web Start 11.121.2.13 x86
  • Using JRE version 1.8.0_121-b13 Java HotSpot(TM) Client VM
0 Answers
Related