I have a java web start application (I deploy a war to Tomcat, user goes to the website and downloads a jnlp which then can be executed). In my build process the jars are signed using a CA authority signed certificate and as far as I can tell without timestamping. The certificate has recently expired.
Extracting jars from the war file and checking them using jarsigner shows:
jar verified.
Warning:
This jar contains entries whose signer certificate has expired.
This jar contains signatures that do not include a timestamp. Without a timestamp, users may not be able to validate this jar after any of the signer certificates expire (as early as 2020-02-24).
It appears that:
- the users can still launch the java web start applications
- the build job still runs and is able to sign with the expired certificate
- deploying a newly built version that has been signed with the expired certificate still works and the app still launches
Now I am wondering what is the impact of that expiry, and should I even bother with renewing the certificate and adding to the keystore?
Update:
Server:
- Tomcat Version Apache Tomcat/9.0.10
- JVM Version 1.8.0_181-b13
Client:
- Java Web Start 11.121.2.13 x86
- Using JRE version 1.8.0_121-b13 Java HotSpot(TM) Client VM