[ 
https://issues.apache.org/jira/browse/DERBY-6234?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13907573#comment-13907573
 ] 

Rick Hillegas commented on DERBY-6234:
--------------------------------------

Hi Kim,

It appears to me that cdevcsecure21547.dita is a section about setting 
username/password pairs for BUILTIN authentication. It doesn't mention LDAP. So 
I think this section should be removed.

I don't see any reason that the derby.user.* family of properties can't be set 
at the system level for LDAP. Thanks.

> Remove references to BUILTIN authentication from the user guides
> ----------------------------------------------------------------
>
>                 Key: DERBY-6234
>                 URL: https://issues.apache.org/jira/browse/DERBY-6234
>             Project: Derby
>          Issue Type: Improvement
>          Components: Documentation
>    Affects Versions: 10.11.0.0
>            Reporter: Rick Hillegas
>            Assignee: Kim Haase
>         Attachments: DERBY-6234.diff, DERBY-6234.stat, DERBY-6234.zip
>
>
> BUILTIN authentication is a scheme suitable only for regression tests. Many 
> security problems make it inappropriate for production use. To avoid 
> confusion and prevent users from selecting this insecure authentication 
> scheme, we should remove references to it from our user documentation.



--
This message was sent by Atlassian JIRA
(v6.1.5#6160)

Reply via email to