You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@knox.apache.org by "Philip Zampino (Jira)" <ji...@apache.org> on 2019/11/18 16:33:00 UTC

[jira] [Issue Comment Deleted] (KNOX-2127) ZooKeeperAliasService mishandles mixed-case alias keys properly

     [ https://issues.apache.org/jira/browse/KNOX-2127?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Philip Zampino updated KNOX-2127:
---------------------------------
    Comment: was deleted

(was: It seems that the local keystore implementation honors the mixed-case (at least with the JDK on my machine).)

> ZooKeeperAliasService mishandles mixed-case alias keys properly
> ---------------------------------------------------------------
>
>                 Key: KNOX-2127
>                 URL: https://issues.apache.org/jira/browse/KNOX-2127
>             Project: Apache Knox
>          Issue Type: Bug
>          Components: Server
>    Affects Versions: 1.3.0
>            Reporter: Philip Zampino
>            Assignee: Philip Zampino
>            Priority: Major
>             Fix For: 1.4.0
>
>
> The ZooKeeperAliasService mishandles mixed-case alias keys. Due to JDK-4891485, the getPasswordFromAliasForCluster(String, String, boolean) implementation assumes the alias key should be lower-cased. However, it enforces no such requirement when an alias is added. Hence, it's possible to add a mixed-case alias key, but impossible to retrieve the value thereof.
> If this lower-case requirement is necessary, then the implementation must enforce it consistently. The add methods must also lower-case the alias keys.



--
This message was sent by Atlassian Jira
(v8.3.4#803005)