[
https://jira.jboss.org/browse/JBAS-8159?page=com.atlassian.jira.plugin.sy...
]
Scott Marlow updated JBAS-8159:
-------------------------------
Fix Version/s: 7.0.0.M1
Question: How complete is the patch for securing the JSR-160 (example) code in AS 5? I
am wondering if its complete or known to need further work (as a solution to patch the
current JSR-160 example code in AS 5).
In addition to looking at any new proposals for securing JSR-160 support, we should look
at merging any parts of this contribution to AS-7 release (that make sense). Marking as
fix for AS 7 to support that separate effort.
Secure jmx-remoting.sar
-----------------------
Key: JBAS-8159
URL:
https://jira.jboss.org/browse/JBAS-8159
Project: JBoss Application Server
Issue Type: Feature Request
Security Level: Public(Everyone can see)
Components: JMX
Affects Versions: JBossAS-5.1.0.GA
Environment: JBossAS 5.1.0 GA
Reporter: Xavier MOGHRABI
Assignee: Scott Marlow
Fix For: 7.0.0.M1
Attachments: jboss-service.xml, jbossas-jmx-remoting-src.jar
JBossAS 5.1.0 GA provides jmx-remoting.sar compliant to JSR 160. Unfortunately the
service is not secured and doesn't provide any way to secure it.
However the JMX API provides several mechanisms allowing authentication and
authorization. Authentication can easily done against a login-module.
A forwarder can be implemented to extend the authorization against a role based
mechanism.
--
This message is automatically generated by JIRA.
-
If you think it was sent incorrectly contact one of the administrators:
https://jira.jboss.org/secure/Administrators.jspa
-
For more information on JIRA, see:
http://www.atlassian.com/software/jira