<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: JarSigner cannot verify signature of ics64.jar with recent OpenJDK in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/JarSigner-cannot-verify-signature-of-ics64-jar-with-recent/m-p/145313#M7010</link>
    <description>&lt;P&gt;I recommend opening a TAC case, but I suspect it's because we don't support that version of OpenJDK (in which case, it'd be an RFE to support it).&lt;/P&gt;</description>
    <pubDate>Sun, 03 Apr 2022 00:01:53 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2022-04-03T00:01:53Z</dc:date>
    <item>
      <title>JarSigner cannot verify signature of ics64.jar with recent OpenJDK</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/JarSigner-cannot-verify-signature-of-ics64-jar-with-recent/m-p/145193#M7009</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Our customer is using SSL Extender and ESOD. One of their users who recently installed Java is getting&amp;nbsp;"Check Point Deployment Shell Internal Error"&lt;/P&gt;&lt;P&gt;Checking cshell.elg on the client I see following&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;INFO [global] (Log log) [General] Java vendor: Eclipse Adoptium (verion 11.0.14.1)
INFO [global] (Log log) [General] Certificate checking: Path does not chain with any of the trust anchors
INFO [global] (Log log) [Component] has_invalid_cert and has_unsigned_entry are false
INFO [global] (Log log) [Component] Verify - Returning false
INFO [global] (Log log) [Component] Failed to verify C:\Users\admin\AppData\Local\Temp\CSHELL\ics64\100001160\ics64.jar.tmp using JarSigner&lt;/LI-CODE&gt;&lt;P&gt;Trying a bit older version, it still does not work&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;INFO [global] (Log log) [General] Java vendor: Eclipse Foundation (verion 11.0.12)                                                          
INFO [global] (Log log) [General] Certificate checking: Path does not chain with any of the trust anchors                                   
INFO [global] (Log log) [Component] has_invalid_cert and has_unsigned_entry are false                                                       
INFO [global] (Log log) [Component] Verify - Returning false                                                                                
INFO [global] (Log log) [Component] Failed to verify C:\Users\admin\AppData\Local\Temp\CSHELL\ics64\100001160\ics64.jar.tmp using JarSigner &lt;/LI-CODE&gt;&lt;P&gt;When using old Oracle OpenJDK it works fine and cshell.elg on the client shows:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;INFO [global] (Log log) [General] Java vendor: Oracle Corporation (verion 11.0.2)
INFO [global] (Log log) [Component] Verify - Returning true
INFO [global] (Log log) [Component] Verified C:\Users\admin\AppData\Local\Temp\CSHELL\ics64\100001160\ics64.jar.tmp using JarSigner&lt;/LI-CODE&gt;&lt;P&gt;What can be done so that newer versions of OpenJDK can be used? I tried latest Microsoft OpenJDK 11 too, with the same results.&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Mar 2022 22:30:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/JarSigner-cannot-verify-signature-of-ics64-jar-with-recent/m-p/145193#M7009</guid>
      <dc:creator>Srdjan_B</dc:creator>
      <dc:date>2022-03-31T22:30:19Z</dc:date>
    </item>
    <item>
      <title>Re: JarSigner cannot verify signature of ics64.jar with recent OpenJDK</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/JarSigner-cannot-verify-signature-of-ics64-jar-with-recent/m-p/145313#M7010</link>
      <description>&lt;P&gt;I recommend opening a TAC case, but I suspect it's because we don't support that version of OpenJDK (in which case, it'd be an RFE to support it).&lt;/P&gt;</description>
      <pubDate>Sun, 03 Apr 2022 00:01:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/JarSigner-cannot-verify-signature-of-ics64-jar-with-recent/m-p/145313#M7010</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-04-03T00:01:53Z</dc:date>
    </item>
  </channel>
</rss>

