ant-user mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Ivan Ivanov <rambiusparkisan...@yahoo.com>
Subject Re: [signjar] prevent double signing
Date Thu, 04 Nov 2004 16:21:38 GMT

--- Stefan Bodewig <bodewig@apache.org> wrote:

> 
> A signed jar contains the signature in a file named
> ALIAS.SF (ALIAS is
> a placeholder here) inside of the META-INF
> directory.  

Well, Stefan, having in mind your remark, the original
requestor has the following "dirty" solution simply
unjar in a temp dir the jar, check for the
availability of ALIAS.SF and if present, does not sign
the jar; else signs it. 

> All the code in signjar does is checking for this 
> file. 
> It doesn not check whether the file contains
> anything useful or the
> signature is valid.

The cleaner solution is to use SignJar.isSigned(File)
(maybe in a custom ant task) to check the jar.

> 
> Should have been in there for longer.  Let's see
>
<http://cvs.apache.org/viewcvs.cgi/ant/src/main/org/apache/tools/ant/taskdefs/SignJar.java?r1=1.7&r2=1.8>
> has been added for Ant 1.4.
> 
> Stefan
> 
>
---------------------------------------------------------------------
> To unsubscribe, e-mail:
> user-unsubscribe@ant.apache.org
> For additional commands, e-mail:
> user-help@ant.apache.org
> 
> 



		
__________________________________ 
Do you Yahoo!? 
Check out the new Yahoo! Front Page. 
www.yahoo.com 
 


---------------------------------------------------------------------
To unsubscribe, e-mail: user-unsubscribe@ant.apache.org
For additional commands, e-mail: user-help@ant.apache.org


Mime
View raw message