Valid signature, trusted
certificate: Pass applet
Valid signature, flagged
certificate: Block applet
No signature: Open applet
and examine code
Invalid signature: Block
applet
IWSVA validates an applet
signature by checking the expiration date of all certificates in the chain
IWSVA strips certificates
that it cannot verify (trust)
IWSVA allows to connect
back to the originating server
It does not allow an applet
to write or read data on a local disk, or to bind to a local port