Since is a potential security issue to store this in the recovery state, you have to be
able to override it. If it means the admin initiating the recovery has to supply it, so be
it. You can't assume that because application managed security originally created the
connection, that this has to be used for recovery. The application may have secure ways of
obtaining this info. That same mechanism or equivalently strong approach would have to be
setup for recovery.
View the original post :
http://www.jboss.com/index.html?module=bb&op=viewtopic&p=4009648#...
Reply to the post :
http://www.jboss.com/index.html?module=bb&op=posting&mode=reply&a...