glassfish
  1. glassfish
  2. GLASSFISH-277

Disable the server's security manager by default ...

    Details

    • Type: Improvement Improvement
    • Status: Resolved
    • Priority: Major Major
    • Resolution: Fixed
    • Affects Version/s: 9.0pe
    • Fix Version/s: 9.0pe
    • Component/s: security
    • Labels:
      None
    • Environment:

      Operating System: All
      Platform: All

    • Issuezilla Id:
      277

      Description

      It has been decided that the Java 2 Platform security manager will be disabled
      by default for the GlassFish server.

        Activity

        Hide
        km105526 added a comment -

        Make sure that the domain.xml template and code is modified appropriately.

        Show
        km105526 added a comment - Make sure that the domain.xml template and code is modified appropriately.
        Hide
        km105526 added a comment -

        <checkins>
        glassfish/appserv-commons/src/java/com/sun/enterprise/util/SystemPropertyConstants.java?r1=1.12&r2=1.13
        </checkins>

        Show
        km105526 added a comment - <checkins> glassfish/appserv-commons/src/java/com/sun/enterprise/util/SystemPropertyConstants.java?r1=1.12&r2=1.13 </checkins>
        Hide
        Shing Wai Chan added a comment -

        glassfish/appserv-core/src/java/com/sun/enterprise/security/SecurityLifecycle.java
        new revision: 1.4; previous revision: 1.3

        Show
        Shing Wai Chan added a comment - glassfish/appserv-core/src/java/com/sun/enterprise/security/SecurityLifecycle.java new revision: 1.4; previous revision: 1.3
        Hide
        Shing Wai Chan added a comment -

        need to update domain.xml templates in PE (security manager off by default)
        and EE (security manager on by default)

        Show
        Shing Wai Chan added a comment - need to update domain.xml templates in PE (security manager off by default) and EE (security manager on by default)
        Hide
        km105526 added a comment -

        Now we realized that -Djava.security.manager can indeed be used, so making sure
        that com.sun.aas.installRoot is available to the app server VM.

        Assigning to Shing Wai for further handling.

        Checking in tools/dtds/processLauncher.xml;
        /cvs/glassfish/tools/dtds/processLauncher.xml,v <-- processLauncher.xml
        new revision: 1.13; previous revision: 1.12
        done

        Show
        km105526 added a comment - Now we realized that -Djava.security.manager can indeed be used, so making sure that com.sun.aas.installRoot is available to the app server VM. Assigning to Shing Wai for further handling. Checking in tools/dtds/processLauncher.xml; /cvs/glassfish/tools/dtds/processLauncher.xml,v <-- processLauncher.xml new revision: 1.13; previous revision: 1.12 done
        Hide
        Shing Wai Chan added a comment -

        Checking in SecurityLifecycle.java;
        /cvs/glassfish/appserv-core/src/java/com/sun/enterprise/security/SecurityLifecycle.java,v
        <-- SecurityLifecycle.java
        new revision: 1.5; previous revision: 1.4
        Checking in SystemPropertyConstants.java;
        /cvs/glassfish/appserv-commons/src/java/com/sun/enterprise/util/SystemPropertyCo
        nstants.java,v <-- SystemPropertyConstants.java
        new revision: 1.14; previous revision: 1.13
        One can turn on and off security manager by specifying or removing
        -Djava.security.manager now.
        Assigned to Kedar to add the above option to domain.xml template.

        Show
        Shing Wai Chan added a comment - Checking in SecurityLifecycle.java; /cvs/glassfish/appserv-core/src/java/com/sun/enterprise/security/SecurityLifecycle.java,v <-- SecurityLifecycle.java new revision: 1.5; previous revision: 1.4 Checking in SystemPropertyConstants.java; /cvs/glassfish/appserv-commons/src/java/com/sun/enterprise/util/SystemPropertyCo nstants.java,v <-- SystemPropertyConstants.java new revision: 1.14; previous revision: 1.13 One can turn on and off security manager by specifying or removing -Djava.security.manager now. Assigned to Kedar to add the above option to domain.xml template.
        Hide
        Shing Wai Chan added a comment -

        Turn off security manager on client side by default
        Checking in Main.java;
        /cvs/glassfish/appserv-core/src/java/com/sun/enterprise/appclient/Main.java,v
        <-- Main.java
        new revision: 1.25; previous revision: 1.24
        done

        Show
        Shing Wai Chan added a comment - Turn off security manager on client side by default Checking in Main.java; /cvs/glassfish/appserv-core/src/java/com/sun/enterprise/appclient/Main.java,v <-- Main.java new revision: 1.25; previous revision: 1.24 done
        Hide
        km105526 added a comment -

        Fixed.

        Show
        km105526 added a comment - Fixed.
        Hide
        km105526 added a comment -

        Corrected build number.

        Show
        km105526 added a comment - Corrected build number.

          People

          • Assignee:
            km105526
            Reporter:
            km105526
          • Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

            • Created:
              Updated:
              Resolved: