[gatein-issues] [JBoss JIRA] (GTNPORTAL-2175) The default OAuth signing key should NOT be automatically generated if it does not exist

Trong Tran (Created) (JIRA) jira-events at lists.jboss.org
Tue Oct 18 00:18:45 EDT 2011


The default OAuth signing key should NOT be automatically generated if it does not exist
----------------------------------------------------------------------------------------

                 Key: GTNPORTAL-2175
                 URL: https://issues.jboss.org/browse/GTNPORTAL-2175
             Project: GateIn Portal
          Issue Type: Bug
      Security Level: Public (Everyone can see)
         Environment: 

            Reporter: Trong Tran
             Fix For: 3.2.0-M02


Today the oauthkey.pem is generated automatically if it does not exist. The file contains RSA based private key for signing request of OAuth authentication.

This is not a reasonable behaviour to OAuth signing request authentication. A pair public/private key should be pre-defined for use properly

--
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators: https://issues.jboss.org/secure/ContactAdministrators!default.jspa
For more information on JIRA, see: http://www.atlassian.com/software/jira

        


More information about the gatein-issues mailing list