db-derby-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Kim Haase (JIRA)" <j...@apache.org>
Subject [jira] [Commented] (DERBY-6234) Remove references to BUILTIN authentication from the user guides
Date Thu, 20 Feb 2014 21:04:22 GMT

    [ https://issues.apache.org/jira/browse/DERBY-6234?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13907494#comment-13907494
] 

Kim Haase commented on DERBY-6234:
----------------------------------

Then perhaps cdevcsecure21547.dita, which talks about using derby.user.UserName, should also
be revived along with its subtopics, rewritten (shrunk), and moved under "LDAP directory service"?
Maybe the subtopics should be made into subsections of cdevcsecure21547.dita to avoid excessive
nesting (the "LDAP directory service" subsections are already 5 levels deep)?

> Remove references to BUILTIN authentication from the user guides
> ----------------------------------------------------------------
>
>                 Key: DERBY-6234
>                 URL: https://issues.apache.org/jira/browse/DERBY-6234
>             Project: Derby
>          Issue Type: Improvement
>          Components: Documentation
>    Affects Versions: 10.11.0.0
>            Reporter: Rick Hillegas
>            Assignee: Kim Haase
>         Attachments: DERBY-6234.diff, DERBY-6234.stat, DERBY-6234.zip
>
>
> BUILTIN authentication is a scheme suitable only for regression tests. Many security
problems make it inappropriate for production use. To avoid confusion and prevent users from
selecting this insecure authentication scheme, we should remove references to it from our
user documentation.



--
This message was sent by Atlassian JIRA
(v6.1.5#6160)

Mime
View raw message