accumulo-notifications mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "David Medinets (JIRA)" <j...@apache.org>
Subject [jira] [Updated] (ACCUMULO-586) sign jars when building a release
Date Sat, 19 Apr 2014 21:13:17 GMT

     [ https://issues.apache.org/jira/browse/ACCUMULO-586?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]

David Medinets updated ACCUMULO-586:
------------------------------------

    Priority: Minor  (was: Major)

> sign jars when building a release
> ---------------------------------
>
>                 Key: ACCUMULO-586
>                 URL: https://issues.apache.org/jira/browse/ACCUMULO-586
>             Project: Accumulo
>          Issue Type: Improvement
>            Reporter: Adam Fuchs
>            Priority: Minor
>
> As part of the release process we should include the following steps:
> 1. Generate a new key pair
> 2. Use it to sign the jars
> 3. Generate a java security policy file that includes the public key
> 4. Destroy the private key
> This opens up the possibility of using the java security manager to restrict what code
can be loaded and increase the security of Accumulo.



--
This message was sent by Atlassian JIRA
(v6.2#6252)

Mime
View raw message