That was it... funny, as I was typing "excellent" I had a feeling in my
gut that this would be the weak link in the chain! Actually, the weak link
is my understanding of certificates... just can't quite get my head around
it. So, the jar file is signed, but what's to stop someone signing their
own jar file with their own keys, surely java security wouldn't know the
difference??
Thanks a lot for your help, I'm back on track!
tomas