Re: [controller-dev] [infrautils-dev] credentials for REST to jolokia/exec/org.opendaylight.infrautils.diagstatus

2018-04-10 Thread Ryan Goulding
> > it's up for interpretation as far as vulnerabilities. > Yeah, I am all for implementing good practice by default too, and I understand this is not optimal. I purely wanted to make sure AAA didn't have a huge bug in the middle of it, which was my initial concern sitting in the Red Sox game whe

Re: [controller-dev] [infrautils-dev] credentials for REST to jolokia/exec/org.opendaylight.infrautils.diagstatus

2018-04-10 Thread Michael Vorburger
On Mon, Apr 9, 2018 at 7:49 PM, Jamo Luhrsen wrote: > it's up for interpretation as far as vulnerabilities. > > seems by default, the vulnerability is there. However, one can argue that > users need > to RTFM, go restart their deployment, ya da ya da ya da (hi robert...) to > avoid > the non-auth