[ https://issues.apache.org/jira/browse/LOG4J2-1896?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16178188#comment-16178188 ]
ASF subversion and git services commented on LOG4J2-1896: --------------------------------------------------------- Commit ec5200a74bd3988a23e6ba60d66b5f1203787a8f in logging-log4j2's branch refs/heads/master from rpopma [ https://git-wip-us.apache.org/repos/asf?p=logging-log4j2.git;h=ec5200a ] LOG4J2-1896 use factory method instead of constructor > Update classes in org.apache.logging.log4j.core.net.ssl in APIs from String > to char[] for passwords > --------------------------------------------------------------------------------------------------- > > Key: LOG4J2-1896 > URL: https://issues.apache.org/jira/browse/LOG4J2-1896 > Project: Log4j 2 > Issue Type: Improvement > Components: Configurators > Reporter: Gary Gregory > Assignee: Remko Popma > Fix For: 2.10.0 > > > Update {{org.apache.logging.log4j.core.net.ssl.StoreConfiguration}} from a > {{String}} to {{char[]}} to represent its password. > The goal is to reduce the security risk of using a String for a password. See > https://stackoverflow.com/questions/8881291/why-is-char-preferred-over-string-for-passwords -- This message was sent by Atlassian JIRA (v6.4.14#64029)