[
https://issues.apache.org/jira/browse/SYNCOPE-1996?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18112895#comment-18112895
]
ASF subversion and git services commented on SYNCOPE-1996:
----------------------------------------------------------
Commit e00f4fd905c8c1ae9e131eab6174f9585c5a04d2 in syncope's branch
refs/heads/4_1_X from Francesco Chicchiriccò
[ https://gitbox.apache.org/repos/asf?p=syncope.git;h=e00f4fd905 ]
[SYNCOPE-1996] Updating docs
> Security production mode
> ------------------------
>
> Key: SYNCOPE-1996
> URL: https://issues.apache.org/jira/browse/SYNCOPE-1996
> Project: Syncope
> Issue Type: Improvement
> Components: core
> Reporter: Francesco Chicchiriccò
> Assignee: Francesco Chicchiriccò
> Priority: Major
> Labels: security
> Fix For: 4.0.8, 4.1.3, 5.0.0
>
>
> A few operations, including:
> * AES key truncate / padding
> * JWK key padding
> * default admin and anonymous credentials check
> were originally introduced to support the initial setup and configuration
> phases.
> The same features, however, when considered in a production context, might
> lead to unwanted disclosures in case the provided suggestions are not
> thoroughly followed.
> It makes sense, then, to introduce a new configuration property for Core
> which explicitly indicates when the system is operating in production mode.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)