You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@qpid.apache.org by "Rob Godfrey (JIRA)" <ji...@apache.org> on 2014/07/24 13:30:38 UTC

[jira] [Updated] (QPID-5922) [Java Broker] By default restrict the use of PLAIN authentication to secure channels

     [ https://issues.apache.org/jira/browse/QPID-5922?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Rob Godfrey updated QPID-5922:
------------------------------

    Status: Reviewable  (was: In Progress)

> [Java Broker] By default restrict the use of PLAIN authentication to secure channels
> ------------------------------------------------------------------------------------
>
>                 Key: QPID-5922
>                 URL: https://issues.apache.org/jira/browse/QPID-5922
>             Project: Qpid
>          Issue Type: Improvement
>          Components: Java Broker
>            Reporter: Rob Godfrey
>            Assignee: Rob Godfrey
>             Fix For: 0.29
>
>
> PLAIN authentication sends passwords in the clear - in general this should not be used over communication channels which are not themselves encrypted.
> For any given authentication provider we should allow the user to set the subset of SASL mechanisms which should not be offered if the attempt to authenticate is not occurring on a secure channel.



--
This message was sent by Atlassian JIRA
(v6.2#6252)

---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscribe@qpid.apache.org
For additional commands, e-mail: dev-help@qpid.apache.org