You are viewing a plain text version of this content. The canonical link for it is here.
Posted to notifications@accumulo.apache.org by "David Medinets (JIRA)" <ji...@apache.org> on 2014/04/19 23:13:17 UTC

[jira] [Updated] (ACCUMULO-586) sign jars when building a release

     [ https://issues.apache.org/jira/browse/ACCUMULO-586?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

David Medinets updated ACCUMULO-586:
------------------------------------

    Priority: Minor  (was: Major)

> sign jars when building a release
> ---------------------------------
>
>                 Key: ACCUMULO-586
>                 URL: https://issues.apache.org/jira/browse/ACCUMULO-586
>             Project: Accumulo
>          Issue Type: Improvement
>            Reporter: Adam Fuchs
>            Priority: Minor
>
> As part of the release process we should include the following steps:
> 1. Generate a new key pair
> 2. Use it to sign the jars
> 3. Generate a java security policy file that includes the public key
> 4. Destroy the private key
> This opens up the possibility of using the java security manager to restrict what code can be loaded and increase the security of Accumulo.



--
This message was sent by Atlassian JIRA
(v6.2#6252)