[jboss-dev-forums] [JBoss AS7 Development] - Re: Is 7.0.0.Final (Everything) ready and stable for production?
Jason Greene
do-not-reply at jboss.com
Mon Aug 1 14:21:33 EDT 2011
Jason Greene [http://community.jboss.org/people/jason.greene] created the discussion
"Re: Is 7.0.0.Final (Everything) ready and stable for production?"
To view the discussion, visit: http://community.jboss.org/message/618660#618660
--------------------------------------------------------------
Having the ability to "mask" passwords in configuration is on the 7.1 schedule. However, I just want to add that have seen very few people use this feature in a way that has better security than not masking your passwords. If you do not require human interaction on boot (typing in a password, providing a removable key device etc), then these passwords are trivially reversible. You can also have tighter file perms on the keystore, but you can accomplish the same thing by using good file perms on standalone/domain.xml.
--------------------------------------------------------------
Reply to this message by going to Community
[http://community.jboss.org/message/618660#618660]
Start a new discussion in JBoss AS7 Development at Community
[http://community.jboss.org/choose-container!input.jspa?contentType=1&containerType=14&container=2225]
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.jboss.org/pipermail/jboss-dev-forums/attachments/20110801/e48c3cbc/attachment.html
More information about the jboss-dev-forums
mailing list