You are viewing a plain text version of this content. The canonical link for it is here.
Posted to issues@karaf.apache.org by "Jean-Baptiste Onofré (JIRA)" <ji...@apache.org> on 2015/08/12 06:38:46 UTC

[jira] [Updated] (KARAF-3366) Generate a non-default password on first startup

     [ https://issues.apache.org/jira/browse/KARAF-3366?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Jean-Baptiste Onofré updated KARAF-3366:
----------------------------------------
    Fix Version/s:     (was: 4.0.1)
                       (was: 3.0.5)

> Generate a non-default password on first startup
> ------------------------------------------------
>
>                 Key: KARAF-3366
>                 URL: https://issues.apache.org/jira/browse/KARAF-3366
>             Project: Karaf
>          Issue Type: Wish
>          Components: karaf-security
>    Affects Versions: 3.0.2
>            Reporter: Robert Varga
>            Assignee: Jean-Baptiste Onofré
>
> In OpenDaylight we rely on Karaf as our pre-packaged download, which has the slight caveat that non-customized downloads can easily be vulnerable if users enable ssh with the default password.
> It would be nice if the startup script could generate a random password for root, so the installation is secure by default. Not sure what the impact will be on usability, though.



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)