Uploaded image for project: 'Undertow'
  1. Undertow
  2. UNDERTOW-1629

UndertowLogger.REQUEST_LOGGER logs client certificate issues at error level potentially filling logs

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done
    • Icon: Major Major
    • 2.0.30.Final
    • 2.0.28.Final
    • Core
    • None

      In release 2.0.28 logging was introduced at level error when a client connection does not succeed to authenticate their client certificate. This can easily fill logs during a malicious attack, can the log level be reduced to debug. (Original change to add the logging was:
      UNDERTOW-1580 Improve EJB over HTTPS logging)

            flaviarnn Flavia Rainone
            tomdearman Tom Dearman (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved: