Kathey Marsden (JIRA) wrote:
> Print a security warning to derby.log and network server console if network 
> server is started with -h 0.0.0.0 and security manager, user authentication, 
> and ecrypted userid are not on
> ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------

> 
> Even when started with the localhost default there can be security  issues  
> if the machine itself is not secure.

Can you elaborate on this, or is it documented elsewhere?

A secure environment is always built upon layers, I don't see how
running a Derby network server listening on localhost can add security
risks to a non-secure machine.

Thanks,
Dan.

Reply via email to