Re: Digital Signature for MIDlet?

[email protected]
Newsgroups gmane.comp.java.sun.kvm
Message-ID <[email protected]>
Sorry for the slow reply.

As for accessing protected APIs the problem is very simple: Many device manufacturers and/or carriers grant permissions to sensitive APIs only for very few and specific protection domains (and thus, to applications signed with specific certificates).

Unfortunately, there is no standard policy or agreement which APIs are covered by which protection domains. Some OEMs for example will only allow access to JSR-75 when for applications in the manufacturer domain which means an app developer has to get the attention of the OEM and enter a business arrangement with them.

As a result it is frustrating and nearly impossible for an application developer to get the right signature(s) that allow their app to function correctly on a wide range of devices. To be blunt, some OEMs and operators are using application signing as a way to enforce their business models onto the app developer.
See also my blog on the topic: http://weblogs.java.net/blog/terrencebarr/archive/2007/07/open_technologi.html

What can be done? A unified and industry-wide testing and certification program such as Java Verified (http://www.javaverified.com) should be able to address this and bring some sanity to the system. The problem has been recognized and there are efforts underway to start addressing this. I am currently engaging with some of the Java Verified folks on the topic and will report back to the community soon, I hope.

-- Terrence
[Message sent by forum member 'terrencebarr' (terrencebarr)]

http://forums.java.net/jive/thread.jspa?messageID=228358

===========================================================================
To unsubscribe, send email to [email protected] and include in the body
of the message "signoff KVM-INTEREST".  For general help, send email to
[email protected] and include in the body of the message "help".
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.