Uploaded image for project: 'JDK'
  1. JDK
  2. JDK-4398973

disallow code downloading for bootstrap registry and activator

XMLWordPrintable

    • Icon: Enhancement Enhancement
    • Resolution: Won't Fix
    • Icon: P4 P4
    • None
    • 1.4.0
    • core-libs
    • generic
    • generic

      The new RMI security mechanisms allow access control checks to be performed prior to parameter unmarshalling, which is good for avoiding certain kinds of denial of service attacks. However, the read-only bootstrap registry created for secure registries, and the bootstrap activator created for a security rmid, are open to a denial of service attack through code downloading. Since no code should ever need to be downloaded through a bootstrap registry or activator, it would be desirable to disable code downloading for them.

            bscheiflsunw Bob Scheifler (Inactive)
            bscheiflsunw Bob Scheifler (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

              Created:
              Updated:
              Resolved:
              Imported:
              Indexed: