[WSS4J] Re: WSSignEnvelope weak point
Davanum Srinivas <dims-/[email protected]> Tue, 3 Feb 2004 20:10:57 -0800 (PST)
| Newsgroups | gmane.text.xml.wss4j |
|---|---|
| Message-ID | <[email protected]> |
fixed. thanks, dims --- Sashka <[email protected]> wrote: > Hi guys > As I wrote in the question to the mailist, I'm checking if I can use your > code. There is a potential NPE point at WSSignEnvelope class: > > line 202: > X509Certificate[] certs = crypto.getCertificates(user); > if (certs.length <= 0) { //// <<--- Here: certs may be null > throw new WSSecurityException > (WSSecurityException.FAILURE, > "invalidX509Data", new Object[]{"for > Signature"}); > } > > Sincerely, > Jabb. > Have a good day :) ===== Davanum Srinivas - http://webservices.apache.org/~dims/ ------------------------------------------------------- The SF.Net email is sponsored by EclipseCon 2004 Premiere Conference on Open Tools Development and Integration See the breadth of Eclipse activity. February 3-5 in Anaheim, CA. http://www.eclipsecon.org/osdn