How can I download a cryptographically signed version the Java JDK from Oracle?
Posted
by
user53352
on Super User
See other posts from Super User
or by user53352
Published on 2010-10-24T12:14:41Z
Indexed on
2010/12/30
10:56 UTC
Read the original article
Hit count: 193
When going to Oracle's download site (https://cds.sun.com/is-bin/INTERSHOP.enfinity/WFS/CDS-CDS_SMI-Site/en_US/-/USD/ViewProductDetail-Start?ProductRef=java_ee_sdk-6u1u21-wjdk-oth-JPR@CDS-CDS_SMI) to download JDK for EE the download is over HTTP (not HTTPS) and the executable isn't signed. As far as I can tell, there are also no SHA1 hashes published so I have no way to verify that the code hasn't been altered.
Does anybody know of a way to verify this or has Oracle not given any way to make sure this is secure?
© Super User or respective owner