maven-issues mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Tony Chemit (JIRA)" <j...@codehaus.org>
Subject [jira] (MJARSIGNER-35) verbose mode shows keystore password in clear text
Date Fri, 07 Mar 2014 21:03:59 GMT

    [ https://jira.codehaus.org/browse/MJARSIGNER-35?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=342583#comment-342583
] 

Tony Chemit commented on MJARSIGNER-35:
---------------------------------------

@S Yes it should also integrates the MJARSIGNER-34.

I will then add -storepass, -storetype and -providerXXX but not -keypass, as I don't thing
we need it, except if you explain me why? ;)


> verbose mode shows keystore password in clear text
> --------------------------------------------------
>
>                 Key: MJARSIGNER-35
>                 URL: https://jira.codehaus.org/browse/MJARSIGNER-35
>             Project: Maven Jar Signer Plugin
>          Issue Type: Bug
>    Affects Versions: 1.3.1
>            Reporter: Marco Speranza
>            Assignee: Tony Chemit
>             Fix For: 1.3.2
>
>
> If is enabled verbose output, is printed out to the command line the keystore password
in clear text.
> here is an example:
> [INFO] cmd.exe /X /C ""C:\Program Files\Java\jdk1.7.0_51\jre\..\bin\jarsigner.exe" -verbose
-keystore mc-keystore -storepass mypassword



--
This message was sent by Atlassian JIRA
(v6.1.6#6162)

Mime
View raw message