Eclipse Trust Store Precedence for Conflicting Certificates
0 reputation · 08 Sept 2021, 05:06 UTC
Certificate Validation in ECF
Eclipse utilizes the Eclipse Communication Framework (ECF) to handle HTTPS connections for the Marketplace and update sites. Validation logic typically references both the internal secure storage and the JRE cacerts file to establish trust.
Trust Store Conflict
In environments using corporate MITM proxies, a scenario may arise where the internal Eclipse secure storage and the system JRE cacerts contain different certificates for the same Common Name (CN). Because ECF may switch between different underlying providers—such as Apache HttpClient and Java URLConnection—the resolution order for these certificates is not explicitly defined in the documentation.
This creates uncertainty when attempting to override a system-level certificate with a specific version stored within the IDE's secure storage.
- Which trust store takes precedence when identical CNs exist in both the internal secure storage and the JRE
cacerts? - Does the selection order vary depending on whether the request is initiated by the Marketplace client or the Install New Software dialog?