[jboss-dev-forums] [Design of Security on JBoss] - Re: AS 4.2.0 binding to localhost

anil.saldhana@jboss.com do-not-reply at jboss.com
Mon Mar 5 00:41:06 EST 2007


My solutions:
a) Allow the user to only install via the installer. Here we can force the user to choose an admin /passwd.
b) Do not include the jmx-console/web-console anymore with the default distribution. Let it be an on-demand download with an installation notes mandating security of the consoles.

View the original post : http://www.jboss.com/index.html?module=bb&op=viewtopic&p=4024973#4024973

Reply to the post : http://www.jboss.com/index.html?module=bb&op=posting&mode=reply&p=4024973



More information about the jboss-dev-forums mailing list