users@glassfish.java.net

Re: Login failures spams server.log

From: Kumar Jayanti <v.b.kumar.jayanti_at_oracle.com>
Date: Fri, 19 Aug 2011 14:14:33 +0530

On 19-Aug-2011, at 1:05 PM, forums_at_java.net wrote:

> Excellent!
>
> Is there a registered issue on this? If not, allow me to put in my two copper
> pieces' worth: It would be great if there's a default log file for security
> warnings, say 'security.log', placed in the same directory as server.log, and
> rotated in the same way. Perhaps also some configuration options when the
> realm is created and/or in the admin console.
>
Will file an issue for 3.1.2 tracking. Right now i have made it a FINE log that prints the entire trace and the WARNING will be a single line.

What you are suggesting can be done using a Custom Audit Module where all authentication and authorization events are audited.


regards,
kumar
>
>
>
> --
>
> [Message sent by forum member 'tmpsa']
>
> View Post: http://forums.java.net/node/834556
>
>