Uploaded image for project: 'JBoss Enterprise Application Platform'
  1. JBoss Enterprise Application Platform
  2. JBEAP-11867

Elytron server-ssl-context should not use default value when referenced security-domain cannot be used

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done
    • Icon: Critical Critical
    • 7.1.0.ER3
    • 7.1.0.ER1
    • Security
    • None

      When security-domain from server-ssl-context cannot verify X509PeerCertificateChainEvidence then server-ssl-context should rather fail then use some default for X509TrustManager in [1]. It causes that misconfiguration in security domain is masked.

      [1] https://github.com/wildfly-security/wildfly-elytron/blob/656354343e7e28fdee47ab58a03c1cf7042abd55/src/main/java/org/wildfly/security/ssl/SSLContextBuilder.java#L341

              jkalina@redhat.com Jan Kalina (Inactive)
              olukas Ondrej Lukas (Inactive)
              Ondrej Kotek Ondrej Kotek
              Ondrej Kotek Ondrej Kotek
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated:
                Resolved: