users@glassfish.java.net

Re: Security Problem Debuging glassfish

From: <glassfish_at_javadesktop.org>
Date: Thu, 29 Mar 2007 13:14:32 PST

Hi,

In fact the trouble is a lot depper than we can think about. You can hard code your security whotout o probleme. So you do not need to record you passwoerd. But the real probleme i think is the use of Sytem.Out how make a little mess in the Socket message traitment.

The SSL security works well when i do not run glasfish in debug.

Adding Sytem.out.println at the wrong place ( so at the wrong moment) can give some trouble.

But by he way all this complexité make it quite secure. And of course could be usefull for the inter container communication. But of course we must think about how it is more interesting to have a software that now one can improve or a free sources that everybdy can work on it ?
[Message sent by forum member 'hterrolle' (hterrolle)]

http://forums.java.net/jive/thread.jspa?messageID=210512