Uploaded image for project: 'Apache Knox'
  1. Apache Knox
  2. KNOX-882

Bind KnoxTokens to the Requesting Clients

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Open
    • Major
    • Resolution: Unresolved
    • None
    • None
    • Server

    Description

      When issuing the KnoxToken, the requesting client IP address should be added to the resulting token. This IP address will then need to be validated against the IP address of any incoming request that presents the bearer token as proof of identity.

      This will prevent the misappropriation of a token from allowing access from any other machine.

      We will also want to make this binding requirement configurable and provide appropriate warning messages when not in use.

      Attachments

        Activity

          People

            lmccay Larry McCay
            lmccay Larry McCay
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated: