You are viewing a plain text version of this content. The canonical link for it is here.
Posted to issues@maven.apache.org by "Tony Chemit (JIRA)" <ji...@codehaus.org> on 2014/03/07 22:03:59 UTC

[jira] (MJARSIGNER-35) verbose mode shows keystore password in clear text

    [ https://jira.codehaus.org/browse/MJARSIGNER-35?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=342583#comment-342583 ] 

Tony Chemit commented on MJARSIGNER-35:
---------------------------------------

@S Yes it should also integrates the MJARSIGNER-34.

I will then add -storepass, -storetype and -providerXXX but not -keypass, as I don't thing we need it, except if you explain me why? ;)


> verbose mode shows keystore password in clear text
> --------------------------------------------------
>
>                 Key: MJARSIGNER-35
>                 URL: https://jira.codehaus.org/browse/MJARSIGNER-35
>             Project: Maven Jar Signer Plugin
>          Issue Type: Bug
>    Affects Versions: 1.3.1
>            Reporter: Marco Speranza
>            Assignee: Tony Chemit
>             Fix For: 1.3.2
>
>
> If is enabled verbose output, is printed out to the command line the keystore password in clear text.
> here is an example:
> [INFO] cmd.exe /X /C ""C:\Program Files\Java\jdk1.7.0_51\jre\..\bin\jarsigner.exe" -verbose -keystore mc-keystore -storepass mypassword



--
This message was sent by Atlassian JIRA
(v6.1.6#6162)