[ 
https://issues.apache.org/jira/browse/SYNCOPE-1996?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18113183#comment-18113183
 ] 

ASF subversion and git services commented on SYNCOPE-1996:
----------------------------------------------------------

Commit b63fee6b313e5ca6d7e079060b4e21ecdeb24c92 in syncope's branch 
refs/heads/master from Francesco Chicchiriccò
[ https://gitbox.apache.org/repos/asf?p=syncope.git;h=b63fee6b31 ]

[SYNCOPE-1996] Security production mode


> Security production mode
> ------------------------
>
>                 Key: SYNCOPE-1996
>                 URL: https://issues.apache.org/jira/browse/SYNCOPE-1996
>             Project: Syncope
>          Issue Type: Improvement
>          Components: core
>            Reporter: Francesco Chicchiriccò
>            Assignee: Francesco Chicchiriccò
>            Priority: Major
>              Labels: security
>             Fix For: 4.0.8, 4.1.3, 5.0.0
>
>
> A few operations, including:
> * AES key truncate / padding
> * JWK key padding
> * default admin and anonymous credentials check
> were originally introduced to support the initial setup and configuration 
> phases.
> The same features, however, when considered in a production context, might 
> lead to unwanted disclosures in case the provided suggestions are not 
> thoroughly followed.
> It makes sense, then, to introduce a new configuration property for Core 
> which explicitly indicates when the system is operating in production mode.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to