Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: table format fixed.

...

<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="9146d9dba8e5112e-292bc794-4746461c-bc0abfa6-30c3018630ba2914452a1869"><ac:plain-text-body><![CDATA[

[ISO/IEC TR 24772:2010

http://www.aitcnet.org/isai/]

Improperly Verified Signature [XZR]

]]></ac:plain-text-body></ac:structured-macro>

MITRE CWE

CWE-300. Channel accessible by non-endpoint (aka "man-in-the-middle")

 

CWE-319. Cleartext transmission of sensitive information

 

CWE-494. Download of code without integrity check

 

CWE-347. Improper verification of cryptographic signature

...

<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="36d454a081eea8a1-705192f8-454c4176-a84d99aa-e027783705ef4e68e9756636"><ac:plain-text-body><![CDATA[

[[API 2006

AA. References#API 06]]

 

]]></ac:plain-text-body></ac:structured-macro>

<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="da208a8fd62831b2-da6e58dd-44654d06-ac828ceb-395bfdd8ccd076b2e227fa90"><ac:plain-text-body><![CDATA[

[[Bea 2008

AA. References#Bea 08]]

 

]]></ac:plain-text-body></ac:structured-macro>

<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="fed2a2e6f194c81c-447ec93a-476f4d57-abd8abbe-7aa0383f52e74fa2b9c48eef"><ac:plain-text-body><![CDATA[

[[Eclipse 2008

AA. References#Eclipse 08]]

[JAR Signing

http://wiki.eclipse.org/JAR_Signing] and [Signed bundles and protecting against malicious code

http://help.eclipse.org/stable/index.jsp?topic=/org.eclipse.platform.doc.isv/guide]

]]></ac:plain-text-body></ac:structured-macro>

<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="e77b80e3ec44433f-bd3df5b9-44bf4d1d-9579b489-89134fd550f17c7775e89b91"><ac:plain-text-body><![CDATA[

[[Fairbanks 2007

AA. References#Fairbanks 07]]

 

]]></ac:plain-text-body></ac:structured-macro>

<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="0cf0e15b5ed29c3f-9f135154-4fe6403a-857da6b2-e40dd56e7ec7227dcdc340af"><ac:plain-text-body><![CDATA[

[[Flanagan 2005

AA. References#Flanagan 05]]

Chapter 24, The java.util.jar Package

]]></ac:plain-text-body></ac:structured-macro>

<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="16c6495554e3cb51-3d0eaf04-4e144e44-81bc92a3-02346fe50490b21b81b6f50e"><ac:plain-text-body><![CDATA[

[[Gong 2003

AA. References#Gong 03]]

12.8.3, jarsigner

]]></ac:plain-text-body></ac:structured-macro>

<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="e3ea0e7fd9f93312-104e9225-442349dd-836ab7e6-c6ebfa1e4db43ef13bec0ad9"><ac:plain-text-body><![CDATA[

[[Halloway 2001

AA. References#Halloway 01]]

 

]]></ac:plain-text-body></ac:structured-macro>

<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="df2571c16230766c-cac1020e-49bd4485-997885c8-99eadd26fd6e93ea5d983508"><ac:plain-text-body><![CDATA[

[[JarSpec 2008

AA. References#JarSpec 08]]

Signature Validation

 

]]></ac:plain-text-body></ac:structured-macro>

<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="007c6edd0fdeee46-5cc32ff3-422a4b55-90f6af7a-c993e8f1f9d304c2822bce4c"><ac:plain-text-body><![CDATA[

[[Oaks 2001

AA. References#Oaks 01]]

Chapter 12, Digital Signatures, Signed Classes

]]></ac:plain-text-body></ac:structured-macro>

<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="e67957884129476e-5f512107-48f84af0-987996ed-319f3f97a9abde9aa4dbaf4a"><ac:plain-text-body><![CDATA[

[[Muchow 2001

AA. References#Muchow 01]]

 

]]></ac:plain-text-body></ac:structured-macro>

<ac:structured-macro ac:name="unmigrated-wiki-markup" ac:schema-version="1" ac:macro-id="960ff00060a9867a-6016d628-4f974cc9-9c03b73a-1455b1bea459aef12a53d0e7"><ac:plain-text-body><![CDATA[

[[Tutorials 2008

AA. References#Tutorials 08]]

[The JarRunner Class

http://java.sun.com/docs/books/tutorial/deployment/jar/jarrunner.html], [Lesson: API and Tools Use for Secure Code and File Exchanges

http://java.sun.com/docs/books/tutorial/security/sigcert/index.html] and [Verifying Signed JAR Files

http://java.sun.com/docs/books/tutorial/deployment/jar/verify.html]

]]></ac:plain-text-body></ac:structured-macro>

...