Self-signed certs not working after Private Cloud/Java upgrade

Not applicable

When you upgrade your Private Cloud (OPDK/on-prem) version you will likely upgrade your java version too. This can cause problems with some self-signed certificates. The problem occurs between Java 1.7_79 and 1.7_85 (Java 7u79 and 7u85)

I haven't been able to pin down which particular change in Java causes it yet, but the following are prime suspects:

  • Change to disallow the downgrading of RSA key
  • Change to default to 1024 bit DH key size
  • Removal of root certs, one of which may have been used for self-signing
  • Cessation of reverse name lookups for raw IP addresses
2 0 277
0 REPLIES 0