JBoss Community

AS7: Utilising masked passwords via the vault

new comment by mentallurg View all comments on this document

JBoss vault is not safe. It gives you false feeling of safety. You disclose the password to access the vault via KEYSTORE_PASSWORD. Everyone can easily decrypt all the passwords you have encrypted.

 

Unfortunately JBoss does not help users to understand it and to be aware of security problems.