users@glassfish.java.net

Re: 3.1 Security One Pager

From: <glassfish_at_javadesktop.org>
Date: Tue, 01 Jun 2010 15:04:27 PDT

Please consider these comments:

1. 4.1.1 - the URL in this paragraph points to the edit page.

2. 4.1.5.3.1 and 4.1.5.4.1 - Is there any CLI change needed here to provide the same capability via the CLI?

3. GENERAL: When invoking a command on an instance from the DAS, we need to ensure that the DAS has proper authentication/authorization to be able to execute the command. We were hoping that this security project would help with that, but I don't see it covered anywhere. One issue that we have for this is 12045:

https://glassfish.dev.java.net/issues/show_bug.cgi?id=12045

Any thoughts on this?

Thanks.
Tom
[Message sent by forum member 'tmueller']

http://forums.java.net/jive/thread.jspa?messageID=472323