Uploaded image for project: 'Geronimo'
  1. Geronimo
  2. GERONIMO-5401

Geronimo encrypts empty passwords

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Major
    • Resolution: Fixed
    • 2.1.5
    • 2.1.7, 2.2.1, 3.0.0
    • databases
    • Security Level: public (Regular issues)
    • None
    • Geronimo tomcat assembly.

    Description

      This can be observed as follows
      1) Create a test db pool with empty passwords. I had used derby embedded xa.
      2) Deploy it.
      3) Check the config.ser. You can see a password string encrypted with

      {Simple}

      or

      {Configured}

      .

      The same behavior can be seen for SystemDatasource.

      This behavior is misleading.

      Attachments

        Activity

          People

            ashishjain Ashish Jain
            ashishjain Ashish Jain
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: