Project

General

Profile

Bug #4194

CILogon download app displays security risk dialog

Added by Matthew Jones over 10 years ago. Updated over 10 years ago.

Status:
Closed
Priority:
High
Assignee:
-
Category:
-
Target version:
-
Start date:
Due date:
% Done:

100%

Milestone:
None
Product Version:
*
Story Points:
Sprint:

Description

When logging into CILogon, the Java Web Start application that launches now triggers a Security Warning because the app is unsigned and does not request Permission attributes. See attached screenshot. This significant;y decreases usability of the sign-in process (building on top of the problems introduced when web start was removed from default java installs). To fix this usability bug, we need to support login and certificate download without a security warning. Ideally, we would also eliminate the JWS dependency altogether as it is typically not installed on end-user machines.

THis may not happen on all OS/Java versions. It triggered for me on Mac OS X 10.7.5, running Java 1.7.0_45 with default security settings (High) and lowered security settings (Medium). I'm not sure how it behaves on other versions.

untrusted-jws-app.png (194 KB) Matthew Jones, 2013-12-04 04:42

211

History

#1 Updated by Matthew Jones over 10 years ago

  • Status changed from New to Closed
  • % Done changed from 0 to 100

Basney and the CILogon team rapidly signed their JWS app and resolved this issue.

Also available in: Atom PDF

Add picture from clipboard (Maximum size: 14.8 MB)