Don't explicitly clear PIN when verifying admin PIN.
The PIN is cleared anyway when the Passphrase object holding the PIN is freed.
This commit is contained in:
@@ -414,7 +414,6 @@ public class SecurityTokenConnection {
|
||||
// delete secrets from memory
|
||||
Arrays.fill(pin, (byte) 0);
|
||||
Arrays.fill(transformedPin, (byte) 0);
|
||||
adminPin.removeFromMemory();
|
||||
|
||||
ResponseApdu response = communicate(verifyPw3Command);
|
||||
if (!response.isSuccess()) {
|
||||
|
||||
Reference in New Issue
Block a user