Hi,

I think it's bad to release a server with default passwords exposed at default installation.

That's why I changed the default startup classes (Spring-based and plain-standalone) to generate random passwords when the account is first created. If the account is persisted, no new password is generated on server restarts.

With changing passwords through service administration at our fingertips, I think we now live in a better (and more secure) world.

  Bernd

Reply via email to