You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@directory.apache.org by "Alex Karasulu (JIRA)" <ji...@apache.org> on 2007/08/24 08:00:30 UTC

[jira] Created: (DIRSERVER-1031) no credentials required to shut down server from in-vm

no credentials required to shut down server from in-vm
------------------------------------------------------

                 Key: DIRSERVER-1031
                 URL: https://issues.apache.org/jira/browse/DIRSERVER-1031
             Project: Directory ApacheDS
          Issue Type: Bug
    Affects Versions: 1.5.0, 1.5.1
            Reporter: Alex Karasulu
             Fix For: 1.5.2


Credentials are not checked when shutting down the server.  

-- 
This message is automatically generated by JIRA.
-
You can reply to this email to add a comment to the issue online.


[jira] Assigned: (DIRSERVER-1031) no credentials required to shut down server from in-vm

Posted by "Alex Karasulu (JIRA)" <ji...@apache.org>.
     [ https://issues.apache.org/jira/browse/DIRSERVER-1031?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Alex Karasulu reassigned DIRSERVER-1031:
----------------------------------------

    Assignee: Alex Karasulu

> no credentials required to shut down server from in-vm
> ------------------------------------------------------
>
>                 Key: DIRSERVER-1031
>                 URL: https://issues.apache.org/jira/browse/DIRSERVER-1031
>             Project: Directory ApacheDS
>          Issue Type: Bug
>    Affects Versions: 1.5.1, 1.5.0
>            Reporter: Alex Karasulu
>            Assignee: Alex Karasulu
>            Priority: Critical
>             Fix For: 1.5.3
>
>
> Credentials are not checked when shutting down the server.  

-- 
This message is automatically generated by JIRA.
-
You can reply to this email to add a comment to the issue online.


[jira] Updated: (DIRSERVER-1031) no credentials required to shut down server from in-vm

Posted by "Emmanuel Lecharny (JIRA)" <ji...@apache.org>.
     [ https://issues.apache.org/jira/browse/DIRSERVER-1031?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Emmanuel Lecharny updated DIRSERVER-1031:
-----------------------------------------

    Fix Version/s:     (was: 1.5.2)
                   1.5.3

Postponed.

> no credentials required to shut down server from in-vm
> ------------------------------------------------------
>
>                 Key: DIRSERVER-1031
>                 URL: https://issues.apache.org/jira/browse/DIRSERVER-1031
>             Project: Directory ApacheDS
>          Issue Type: Bug
>    Affects Versions: 1.5.1, 1.5.0
>            Reporter: Alex Karasulu
>             Fix For: 1.5.3
>
>
> Credentials are not checked when shutting down the server.  

-- 
This message is automatically generated by JIRA.
-
You can reply to this email to add a comment to the issue online.


[jira] Closed: (DIRSERVER-1031) no credentials required to shut down server from in-vm

Posted by "Alex Karasulu (JIRA)" <ji...@apache.org>.
     [ https://issues.apache.org/jira/browse/DIRSERVER-1031?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Alex Karasulu closed DIRSERVER-1031.
------------------------------------

    Resolution: Invalid

In VM control is allowed without credentials.  But we must later on install a security manager to prevent stored procedures from doing this.

> no credentials required to shut down server from in-vm
> ------------------------------------------------------
>
>                 Key: DIRSERVER-1031
>                 URL: https://issues.apache.org/jira/browse/DIRSERVER-1031
>             Project: Directory ApacheDS
>          Issue Type: Bug
>    Affects Versions: 1.5.1, 1.5.0
>            Reporter: Alex Karasulu
>            Assignee: Alex Karasulu
>            Priority: Critical
>             Fix For: 1.5.3
>
>
> Credentials are not checked when shutting down the server.  

-- 
This message is automatically generated by JIRA.
-
You can reply to this email to add a comment to the issue online.


[jira] Updated: (DIRSERVER-1031) no credentials required to shut down server from in-vm

Posted by "Emmanuel Lecharny (JIRA)" <ji...@apache.org>.
     [ https://issues.apache.org/jira/browse/DIRSERVER-1031?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Emmanuel Lecharny updated DIRSERVER-1031:
-----------------------------------------

    Priority: Critical  (was: Major)

Raised to critical, as it seems to be a important security breach

> no credentials required to shut down server from in-vm
> ------------------------------------------------------
>
>                 Key: DIRSERVER-1031
>                 URL: https://issues.apache.org/jira/browse/DIRSERVER-1031
>             Project: Directory ApacheDS
>          Issue Type: Bug
>    Affects Versions: 1.5.1, 1.5.0
>            Reporter: Alex Karasulu
>            Priority: Critical
>             Fix For: 1.5.3
>
>
> Credentials are not checked when shutting down the server.  

-- 
This message is automatically generated by JIRA.
-
You can reply to this email to add a comment to the issue online.