db-derby-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Bernt M. Johnsen (JIRA)" <j...@apache.org>
Subject [jira] Commented: (DERBY-2196) Run standalone network server with security manager by default
Date Tue, 20 Feb 2007 13:13:05 GMT

    [ https://issues.apache.org/jira/browse/DERBY-2196?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel#action_12474436
] 

Bernt M. Johnsen commented on DERBY-2196:
-----------------------------------------

I find the -unsecure option somewhat misleading in sense that one
could be lead to believe that without this options set, Derby would be
secure. 

Wether or not Derby is secure (or more precicely, secure enough for a
certain application) is a rather complex question to answer. Derby
will only be secure enough when the user has evaluated the threat to
his/her application and considered all security features available
(SSL with or without peer authentication, encryption on the disk,
running under security manager with the correct settings in the policy
file, what kind of user authentication to use, use of privileges, SQL
users etc) and decided what fits his/hers application.

The option should be given a name which tells exactly what it does:
Runs Derby without security manager. E.g. -noSecutityManager or
something similar.


> Run standalone network server with security manager by default
> --------------------------------------------------------------
>
>                 Key: DERBY-2196
>                 URL: https://issues.apache.org/jira/browse/DERBY-2196
>             Project: Derby
>          Issue Type: Improvement
>          Components: Network Server, Security
>            Reporter: Daniel John Debrunner
>         Assigned To: Rick Hillegas
>         Attachments: derby-2196-01-print-01.diff, derby-2196-01-print-02.diff, derby-2196-01-print-03.diff,
derby-2196-02-install-01.diff, derby-2196-03-tests-01.diff, secureServer.html, secureServer.html,
secureServer.html, secureServer.html, secureServer.html, secureServer.html
>
>
> From an e-mail discussion:
> ... Derby should match the security  provided by typical client server systems such as
DB2, Oracle, etc. I 
> think in this case system/database owners are trusting the database 
> system to ensure that their system cannot be attacked. So maybe if Derby 
> is booted as a standalone server with no security manager involved, it 
> should install one with a default security policy. Thus allowing Derby 
> to use Java security manager to manage system privileges but not 
> requiring everyone to become familiar with them.
> http://mail-archives.apache.org/mod_mbox/db-derby-dev/200612.mbox/%3c4582FE67.7040308@apache.org%3e
> I imagine such a policy would allow any access to databases under derby.system.home and/or
user.home.
> By standalone I mean the network server was started though the main() method (command
line).

-- 
This message is automatically generated by JIRA.
-
You can reply to this email to add a comment to the issue online.


Mime
View raw message