Uploaded image for project: 'Qpid'
  1. Qpid
  2. QPID-5922

[Java Broker] By default restrict the use of PLAIN authentication to secure channels

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Closed
    • Major
    • Resolution: Fixed
    • None
    • 0.29
    • Broker-J
    • None

    Description

      PLAIN authentication sends passwords in the clear - in general this should not be used over communication channels which are not themselves encrypted.

      For any given authentication provider we should allow the user to set the subset of SASL mechanisms which should not be offered if the attempt to authenticate is not occurring on a secure channel.

      Attachments

        Activity

          People

            rgodfrey Robert Godfrey
            rgodfrey Robert Godfrey
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: