directory-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Colm O hEigeartaigh (Jira)" <j...@apache.org>
Subject [jira] [Created] (DIRSERVER-2328) CreateAuthenticator annotation trust manager improvements
Date Wed, 09 Sep 2020 16:10:00 GMT
Colm O hEigeartaigh created DIRSERVER-2328:
----------------------------------------------

             Summary: CreateAuthenticator annotation trust manager improvements
                 Key: DIRSERVER-2328
                 URL: https://issues.apache.org/jira/browse/DIRSERVER-2328
             Project: Directory ApacheDS
          Issue Type: Task
            Reporter: Colm O hEigeartaigh
            Assignee: Colm O hEigeartaigh
             Fix For: 2.0.0.AM27


There are two problems with the CreateAuthenticator annotation trust manager configuration:
 # delegateSslTrustManagerFQCN + delegateTlsTrustManagerFQCN default to NoVerificationTrustManager,
which is not secure.
 # These values are not plugged through to the DelegatingAuthenticator, which hard-codes NoVerificationTrustManager.



--
This message was sent by Atlassian Jira
(v8.3.4#803005)

---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscribe@directory.apache.org
For additional commands, e-mail: dev-help@directory.apache.org


Mime
View raw message