Re: Security issue with control.sh and ignite.sh

2020-10-07 Thread Ivan Pavlukhin
Hi Sam, Good catch! What exactly should user do to enable JMX? Should the user pass some additional arguments to scripts? It worth mentioning it in the ticket and later in documentation. 2020-10-06 13:50 GMT+03:00, Данилов Семён : > Hello, Igniters! > > I recently got my eye on the fact that we

Security issue with control.sh and ignite.sh

2020-10-06 Thread Данилов Семён
Hello, Igniters! I recently got my eye on the fact that we have JMX enabled by default and it's configured in a very insecure way. Our default JMX parameters are authenticate=false and ssl=false. I propose removing default configuration of JMX altogether, as user must *consciously* and