Details
-
Sub-task
-
Resolution: Done
-
Minor
-
EAP_EWP 5.1.0
-
None
-
Release Notes
-
-
Documented as Resolved Issue
Description
We use org.jboss.security.plugins.FilePassword to avoid storing passwords in clear text. Once created, we'd like to change the file's permission to read-only for regular users in order to ensure that only trusted users can update it.
However, this won't work as the class FilePassword always requires write permission even for decoding the password. The class should be modified so that write permission is only required when create / update the password file.
Attachments
Issue Links
- is blocked by
-
SECURITY-292 org.jboss.security.plugins.FilePassword requires write permission for decoding
- Resolved
- is cloned by
-
SECURITY-292 org.jboss.security.plugins.FilePassword requires write permission for decoding
- Resolved