[jboss-dev-forums] [JBoss AS 7 Development] - AS7 Password Vault on Windows
mentallurg
do-not-reply at jboss.com
Sun Dec 30 09:42:28 EST 2012
mentallurg [https://community.jboss.org/people/mentallurg] commented on the document
"AS7 Password Vault on Windows"
To view all comments on this document, visit: https://community.jboss.org/docs/DOC-17763#comment-11311
--------------------------------------------------
Hi merlin,
JBoss vault is *not safe*. Please keep it in mind. The vault gives you false feeling of safety. You *disclose the password* to access the vault via KEYSTORE_PASSWORD. Everyone can easily decrypt all the passwords you have encrypted.
--------------------------------------------------
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.jboss.org/pipermail/jboss-dev-forums/attachments/20121230/18a3c43d/attachment.html
More information about the jboss-dev-forums
mailing list