mina-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Niklas Gustavsson (Closed) (JIRA)" <j...@apache.org>
Subject [jira] [Closed] (FTPSERVER-428) Allow positive ACL instead of just blacklists
Date Sun, 30 Oct 2011 12:01:32 GMT

     [ https://issues.apache.org/jira/browse/FTPSERVER-428?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]

Niklas Gustavsson closed FTPSERVER-428.
---------------------------------------

    Resolution: Invalid
      Assignee: Niklas Gustavsson

This is already supported using the <ipfilter type="allow">CIDR address ranges</ipfilter>
element.
                
> Allow positive ACL instead of just blacklists
> ---------------------------------------------
>
>                 Key: FTPSERVER-428
>                 URL: https://issues.apache.org/jira/browse/FTPSERVER-428
>             Project: FtpServer
>          Issue Type: Improvement
>          Components: Server
>    Affects Versions: 1.0.6
>            Reporter: Blaine Simpson
>            Assignee: Niklas Gustavsson
>              Labels: ACL, address, blacklist, security, vulnerability
>
> There are tons of situations where it is desirable to allow only specified source addresses
(and ranges) rather than allowing all except for those specified (i.e. blacklisted).  To require
administrators to use a black list when the situation really demands a white list is to encourage
security lapses.

--
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators: https://issues.apache.org/jira/secure/ContactAdministrators!default.jspa
For more information on JIRA, see: http://www.atlassian.com/software/jira

        

Mime
View raw message