this allows to grant specific privileges for these applications as one might deem appropriate, by defining them in a security policy.
please see the Java documentation on how to accomplish this.
the certificate used for signing can be downloaded in the download section.
for a quick reference, the main properties of all the involved certificates are listed below (this output was created with the BoarderZone KeyStoreTool):
========================================================================= Alias: bz-root-ca Entry: trusted certificate at position 2 Added: 2017-05-30 - 07:56:32.984 +0200 Certificate: X.509v3 RSA 4096 bits certificate => VERIFIED - Serial-No.: 0xb1fcf1624767e62e - Signature: SHA256withRSA Subject DN: CN=BoarderZone Root CA, O=BoarderZone.net, L=Zuerich, C=CH Issuer DN: CN=BoarderZone Root CA, O=BoarderZone.net, L=Zuerich, C=CH Validity: not before: 2015-02-06 - 02:10:54.000 +0100 not after: 2035-02-06 - 02:10:54.000 +0100 duration: 20y5d Key usage: CA:max-path-length=2, Key certificate sign, CRL sign Fingerprints: MD5: 4C:4D:C6:B4:E7:9B:7D:99:23:1A:C0:60:69:77:A1:28 SHA-1: E0:DB:BC:CD:44:DB:3F:49:0D:0C:F8:A7:3D:AB:F5:CC:E4:66:3B:8F SHA-256: C6:F6:E7:5B:38:6B:C9:89:8D:57:AF:5A:50:F4:3C:4F:0B:08:00:34: 8F:3F:3A:39:9D:0B:92:FF:FB:6E:29:42 ========================================================================= Alias: bz-trust-ca-v2 Entry: trusted certificate at position 3 Added: 2024-07-20 - 17:09:16.401 +0200 Certificate: X.509v3 RSA 4096 bits certificate => VERIFIED - Serial-No.: 0x3b5780109901a28b - Signature: SHA256withRSA Subject DN: CN=BoarderZone Trust CA v2, O=BoarderZone.net, L=Zuerich, C=CH Issuer DN: CN=BoarderZone Root CA, O=BoarderZone.net, L=Zuerich, C=CH Validity: not before: 2023-12-05 - 14:53:22.000 +0100 not after: 2033-12-05 - 14:53:22.000 +0100 duration: 10y3d Key usage: CA:max-path-length=1, Key certificate sign, CRL sign Fingerprints: MD5: BC:A0:3C:6C:5F:1E:2B:F8:96:61:26:52:95:0D:FA:47 SHA-1: E0:E2:CB:C0:39:BA:35:1E:B8:9E:DE:D2:DE:AE:6E:3B:BB:4A:D6:C4 SHA-256: 3B:53:B1:45:71:AC:53:D7:C3:61:74:0C:DA:57:46:39:B4:04:1B:26: 92:52:D6:DC:E4:4D:3D:C4:44:DC:B1:80 ========================================================================= Alias: bz-qa Entry: trusted certificate at position 1 Added: 2024-07-20 - 17:12:59.649 +0200 Certificate: X.509v3 RSA 2048 bits certificate => VERIFIED - Serial-No.: 0x6390088e3c5f0385 - Signature: SHA256withRSA Subject DN: CN=Quality Assurance, O=BoarderZone.net, L=Zuerich, C=CH - Altern.: ALT[RFC822] = qa@boarderzone.net Issuer DN: CN=BoarderZone Trust CA v2, O=BoarderZone.net, L=Zuerich, C=CH Validity: not before: 2024-07-20 - 16:41:31.000 +0200 not after: 2028-07-20 - 16:41:31.000 +0200 duration: 4y1d Key usage: no-CA, Digital signature, Non-repudiation - Extended: Code signing Fingerprints: MD5: 51:2A:E0:40:A0:33:2D:8E:85:12:EA:B0:47:93:83:75 SHA-1: 2A:C0:84:E1:F7:E8:95:A1:BB:B5:11:42:8F:5C:40:73:CB:58:39:54 SHA-256: F8:81:6E:E0:D8:88:41:C3:F4:02:53:44:FC:7A:BF:4C:F3:8F:41:08: E4:27:F5:46:A5:C5:32:F6:FF:B0:86:00 =========================================================================