SIGN IN SIGN UP

The three java.security.cert.X509CRL accessors no longer let an unchecked exception escape when an indirect CRL carries an entry whose certificateIssuer does not decode to a directoryName, getRevokedCertificates(), getRevokedCertificate(BigInteger) and isRevoked(Certificate) having re-parsed it as GeneralNames.getInstance(...).getNames()[0] in both X509CRLImpl and the deprecated jce.provider.X509CRLObject the registered X509StreamParser.CRL service returns, which also refused the well-formed encoding that names the directoryName after another GeneralName although X509CRLEntryObject read the same CRL correctly, so all six sites now share that sibling's logic, promoted to a package-private static in each of the two packages, and an entry naming no directoryName is treated as having no certificate issuer of its own, which java.security.cert.X509CRLEntry defines as the CRL issuer's, relates to github #2425.

D
David Hook committed
a5e172bfabd7ee576f99f9d203227b2c4616d61f
Parent: 76020c6