The security baselines for the Java Runtime Environment (JRE) at the time of the release of JDK 6u161 are specified in the following table: JAR file validation changes After upgrading to the JDK July CPU release (8u141/7u151/6u161), when executing Java Webstart applications, customers may encounter an exception like “Security Exception: digest missing for …” that prevents the application from loading.The issue is observed in signed JAR files whose manifest contains package version information[1] and does not have a trailing ).While we work towards resolving this issue, in the interim, users can work-around the issue as follows: NOTE: We recommend use of this workaround only if the distributor of the JAR files can "re-sign" the JAR files. Extract the contents of the signed JAR file (e.g.: Disable SHA-1 TLS Server Certificates Any TLS server certificate chain containing a SHA-1 certificate (end-entity or intermediate CA) and anchored by a root CA certificate included by default in Oracle's JDK is now blocked by default.

