[jboss-dev-forums] [JBoss AS 7 Development] - AS7 Password Vault on Windows

mentallurg do-not-reply at jboss.com
Sun Dec 30 09:42:28 EST 2012


mentallurg [https://community.jboss.org/people/mentallurg] commented on the document

"AS7 Password Vault on Windows"

To view all comments on this document, visit: https://community.jboss.org/docs/DOC-17763#comment-11311

--------------------------------------------------
Hi merlin,

JBoss vault  is *not safe*. Please keep it in mind. The vault gives you false feeling of safety. You *disclose the password* to access the vault via KEYSTORE_PASSWORD. Everyone can easily decrypt all the passwords you have encrypted.
--------------------------------------------------

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.jboss.org/pipermail/jboss-dev-forums/attachments/20121230/18a3c43d/attachment.html 


More information about the jboss-dev-forums mailing list