Uploaded image for project: 'JDK'
  1. JDK
  2. JDK-6284592

security hole with IIOP when doing fine grain security + interop Tiger server & Mustang client

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Duplicate
    • Icon: P3 P3
    • 6
    • 6
    • core-svc
    • None

      The SQE test authorization_38 fails all platforms when server side is Tiger based and client side Mustang based.
      It is fine when both sides run Mustang or when server is Mustang based and client Tiger based.
      The symmetric test with rmi/jrmp is fine for every configurations so the issue looks specific to IIOP.
      In that test we use a login/password and a policy file that provide no permission to the MBean involved. With such settings, we expect a SecurityException whatever the user does (create MBean, getAttribute, setAttribute). The issue is that no exception is thrown at all.
      Attached test output.
      ###@###.### 2005-06-13 13:28:52 GMT

            lmalvent Luis-Miguel Alventosa (Inactive)
            yjoan Yves Joan (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

              Created:
              Updated:
              Resolved:
              Imported:
              Indexed: