[ https://issues.apache.org/jira/browse/ACCUMULO-1086?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13588749#comment-13588749 ]
Hudson commented on ACCUMULO-1086: ---------------------------------- Integrated in Accumulo-1.5 #2 (See [https://builds.apache.org/job/Accumulo-1.5/2/]) ACCUMULO-1086 require some user auth, and filter out passwords (Revision 1450929) Result = FAILURE ecn : Files : * /accumulo/branches/1.5/core/src/main/java/org/apache/accumulo/core/client/admin/InstanceOperationsImpl.java * /accumulo/branches/1.5/core/src/main/java/org/apache/accumulo/core/client/admin/TableOperationsImpl.java * /accumulo/branches/1.5/core/src/main/java/org/apache/accumulo/core/client/impl/thrift/ClientService.java * /accumulo/branches/1.5/core/src/main/thrift/client.thrift * /accumulo/branches/1.5/server/src/main/java/org/apache/accumulo/server/client/ClientServiceHandler.java > Configuration secrets exposed via thrift RPC with no authentication > ------------------------------------------------------------------- > > Key: ACCUMULO-1086 > URL: https://issues.apache.org/jira/browse/ACCUMULO-1086 > Project: Accumulo > Issue Type: Bug > Components: master, thrift, tserver > Reporter: Christopher Tubbs > Assignee: Eric Newton > Priority: Blocker > Fix For: 1.5.0 > > > Trace password, keystore passwords, and other sensitive information is > available without any authentication whatsoever, in the thrift client > service. What's the reason for not requiring authentication here? -- This message is automatically generated by JIRA. If you think it was sent incorrectly, please contact your JIRA administrators For more information on JIRA, see: http://www.atlassian.com/software/jira