Issue Details (XML | Word | Printable)

Key: GLASSFISH-18318
Type: Bug Bug
Status: Open Open
Priority: Major Major
Assignee: Snjezana Sevo-Zenzerovic
Reporter: Alex Pineda
Votes: 0
Watchers: 0
Operations

If you were logged in you would be able to see more operations.
glassfish

Install silent option does not store admin password input

Created: 03/Feb/12 06:55 PM   Updated: 19/Mar/13 08:39 PM
Component/s: installation
Affects Version/s: 3.1.2_b20
Fix Version/s: 4.0.1

Time Tracking:
Not Specified

Environment:

OEL6 system. GF 3.1.2 build20. JDK1.7.0_03. Firefox browser 3.6.17. Typical Install option


Tags: 312_qa 3_1_2-exclude 3_1_2-release-note-added 3_1_2-release-notes
Participants: Alex Pineda, Rebecca Parks, scatari, shreedhar_ganapathy, Snjezana Sevo-Zenzerovic and Tom Mueller


 Description  « Hide

With the addition of the Domain Info screen (due to security remediation), the user is given the ability to add an "admin password" that is later used to login to the AdminConsole. The GF Installer provides and option to create a "silent" file that records all the user choices and is only supported in the "Typical" scenario. This "silent" file can later be used to do installation without user interaction.

The issue uncovered is that the option given in the Domain Info (to enter a user admin password) is not being recorded or stored in the "silent" file. The procedure to create the file is as follows:
1. Get the latest build (ogs-3.1.2-b20-unix.sh*)
2. Generate the silent file

  • machine $ ogs-3.1.2-b20-unix.sh -n sfile.txt (file in which all the Install actions are recorded)
    3. Run through the Install Typical option and enter a password in the Domain Info screen (admin123)
    4. Complete the installation steps.
    5. Execute the installation using the "silent" file as follows:
  • machine $ ogs-3.1.2-b20-unix.sh -a sfile.txt -s
    6. After the installation completes, start the domain server
    7. Go to the Admin Console (http://localhost:4848)

You will notice one will be logged into to the Admin Console without any password.

The expected behavior and when executing the same scenario interactively, the AdminConsole login screen is displayed and one has to enter the admin user and admin password.

Reporting this bug as low priority because it's a bit late and perhaps risky to fix. Documenting this issue is sufficient at this time.



scatari made changes - 03/Feb/12 07:51 PM
Field Original Value New Value
Tags 312_qa 312_qa 3_1_2-release-notes
scatari added a comment - 03/Feb/12 07:54 PM - edited

Enabling silent installer to recognize passwords is an enhancement requiring extensive changes. Marking this as Release notes item to be documented. Here is what should be documented as a limitation.

"The generated silent file will not contain any passwords and if such files are used for running automated silent installation, then the created GlassFish domain will provide unauthenticated login mechanism".


scatari made changes - 03/Feb/12 09:21 PM
Tags 312_qa 3_1_2-release-notes 312_qa 3_1_2-exclude 3_1_2-release-notes
Rebecca Parks added a comment - 07/Feb/12 09:54 PM

Added to 3.1.2 Release Notes:

Description

The GlassFish Server installer provides an option to create a silent file that records all user choices and is only supported in the Typical scenario. This silent file can later be used to perform installation without user interaction.

The generated silent file does not contain any passwords. If this file is used for running automated silent installation, the created GlassFish Server domain provides an unauthenticated login mechanism.

Workaround

Use interactive installation if you want the GlassFish Server domain to require passwords.


Rebecca Parks made changes - 07/Feb/12 09:54 PM
Tags 312_qa 3_1_2-exclude 3_1_2-release-notes 312_qa 3_1_2-exclude 3_1_2-release-note-added 3_1_2-release-notes
Alex Pineda made changes - 15/Feb/13 09:35 PM
Fix Version/s future release [ 11148 ]
shreedhar_ganapathy added a comment - 19/Mar/13 05:26 PM

-> Tom Mueller to eval if this will be fixed in 4.0


shreedhar_ganapathy made changes - 19/Mar/13 05:26 PM
Assignee scatari [ scatari ] Tom Mueller [ tmueller ]
Tom Mueller added a comment - 19/Mar/13 08:39 PM

I confirmed that this problem is there in the OSE installer as well as the OGS installer, however, the only way to get a password prompt via the OSE installer is to use the Custom path, not the Typical path.

For 4.0 OSE, the Custom path through the installer is going to be disabled (see GLASSFISH-19680) so there will be no opportunity to enter a password when using the 4.0 OSE installer, so this bug does not need to be fixed for 4.0.


Tom Mueller made changes - 19/Mar/13 08:39 PM
Assignee Tom Mueller [ tmueller ] Snjezana Sevo-Zenzerovic [ snjezana ]
Fix Version/s 4.0.1 [ 16061 ]
Fix Version/s future release [ 11148 ]