admin@glassfish.java.net

Sections of the Security Docplan That Need Content/Guidance]

From: Kevin McDonough <kevin.mcdonough_at_oracle.com>
Date: Wed, 19 Jan 2011 14:33:13 -0500

Hi,

I'm trying to fill in some missing sections in the Glassfish 3.1
Security Guide, and I need some guidance on the content. These sections
are not explicitly linked to new 3.1 features, but instead fall along
the lines of "We need to say something about XYZ."

The docplan expected that this content would be derived from the
WebLogic Server content. Without some guidance/hints/help/pointers as
to what I need to say, I won't be able to have these sections complete
for the 3.1 documentation ship date and we will have to cover them in
first Glassfish doc update.

The approved Security Guide Docplan
(http://wikis.sun.com/display/GlassFish/GlassFishV3.1SecurityDocPlan)
proposed these new topics/sections:

    * /(NEW) Installing GlassFish in a Secure Environment /

   1. /(NEW/WLS)/
   2. /(NEW) Closed Network Installation/

The comparable WLS "Install WebLogic Server in a Secure Manner" section
(http://fmwdocs.us.oracle.com/doclibs/fmw/E10285_01/web.1111/e13705/secure.htm#i1127156)
is specific to WLS, but short. *Is there something analogous we can say
for Glassfish?*


The proposed /Closed Network Installation/ section maps to the extensive
and WLS-centric "Ensuring the Security of Your Production Environment"
chapter
(http://fmwdocs.us.oracle.com/doclibs/fmw/E10285_01/web.1111/e13705/practices.htm).

*Is there something analogous we can say for Glassfish?*



*For the Cluster topics below, what do we need to say for the
proposed *// /Configuring Certificates in Cluster Mode/ *section?*
/
(NEW) Administering Security in Cluster Mode/

   1. /(2.1.1) Security Options (Status: Drafted section that covers
      Dynamic Configuration.)/
   2. /(2.1.1/NEW) Configuring Load Balancer Security (Updated plan:
      Cover elsewhere)
      /
   3. /(2.1.1/NEW) Configuring Web Server Security (Updated plan:
      Cover elsewhere)
      /
   4. /(2.1.1/NEW) Configuring Certificates in Cluster Mode/


Thanks for your help, I really do appreciate it.

-Kevin