[ https://issues.apache.org/jira/browse/KARAF-4620?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15724225#comment-15724225 ]
Xilai Dai commented on KARAF-4620: ---------------------------------- It's only fixed on master, but not backport to karaf-4.0.x branch. > ACL default configuration for feature:start/stop missing > -------------------------------------------------------- > > Key: KARAF-4620 > URL: https://issues.apache.org/jira/browse/KARAF-4620 > Project: Karaf > Issue Type: Bug > Components: karaf-security, karaf-shell > Affects Versions: 4.0.3 > Reporter: Christian Schmülling > Assignee: Jean-Baptiste Onofré > Priority: Minor > Fix For: 4.1.0, 4.0.6 > > > The ACL default configuration down't cover the commands feature:start > feature:stop in org.apache.karaf.command.acl.feature.cfg. > Each user who is able to login is able to start and stop features. > FIX: Add these two lines: > start = admin > stop = admin > HOTFIX at a running system: > config:edit org.apache.karaf.command.acl.feature > config:property-set start admin > config:property-set stop admin > config:update -- This message was sent by Atlassian JIRA (v6.3.4#6332)