Re: Concerning Java and SSL (fwd)

[email protected] (Matthias Jim Knopf)
Newsgroups gmane.comp.security.programming
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----

"Please post this to the Secure Programming list 
<[email protected]>.  There have been many issues unearthed."

... I have heard by a wise guy, so I repost it here, hoping that I might
get some information that might give descition-hints, besides from those
that can be obtained from sun directly.
Main question is: Is it secure "enough" for (near) commercial grade using
those classes mentioned below?

Another question of mine is: Is there a walkable way to use encrypted
streams with non-encrypted in exchange over the same ServerSocket, if
another than SSL encryption would be used?

On Sun, Apr 04, 2004 at 02:11:06PM +0200, Matthias Jim Knopf wrote:

> reading about problems with (open)ssl all the time, I wonder how stable
> and secure the SSL implementation of Java2 (>= 1.4.1) currently is. Are
> there known issues? Or does anybody have a reason for NOT using the
> javax.security.* packages and Classes like SSLSocket and Keystore given by
> Sun?

Greetings, Jim
- -- 
PGP encrypted mails welcome!
Without C, We would only have Pasal, Basi, and obol and Java ... ?!?

-----BEGIN PGP SIGNATURE-----
Version: PGP 6.5.1i

iQCVAwUBQHGwCoftNTssK42HAQFs5gP/XzRFjV/adyd0NZK0T6tohAApoaYiu0lv
NV7EnwCq/xJW7icdYbYa5DIGzD6Ya9BFLevROVT4D1ZBX2NxAuwnnOzukY8+6rL3
CbiHRXXJbm38aeNrDjPZlAMG4E2MioRhRZV+xLZDWHp5zzjkxPTchKPYPXTAnbwt
QYAtsRCXBTc=
=Osbx
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.