[
https://issues.apache.org/jira/browse/ARTEMIS-551?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15314321#comment-15314321
]
ASF subversion and git services commented on ARTEMIS-551:
---------------------------------------------------------
Commit f84018a417cee7bbb1261f5ae36e51c9ddef748f in activemq-artemis's branch
refs/heads/master from [~msmerek]
[ https://git-wip-us.apache.org/repos/asf?p=activemq-artemis.git;h=f84018a ]
ARTEMIS-551 Obfuscate truststore password
Obfuscate truststore password in TransportConfiguration.toString()
in the same way as keystore. The password will not be logged in
plain text when bridge is connected.
> ActiveMQ logs truststore password in plain text
> -----------------------------------------------
>
> Key: ARTEMIS-551
> URL: https://issues.apache.org/jira/browse/ARTEMIS-551
> Project: ActiveMQ Artemis
> Issue Type: Bug
> Affects Versions: 1.2.0
> Reporter: Martin Smerek
> Assignee: Justin Bertram
>
> ActiveMQ logs trust-store-password in plain text during bridge connection.
> 1. Configure two ActiveMQ servers for data replication over netty-ssl as
> collocated.
> 2. Start both servers and check logs for "221027: Bridge
> ClusterConnectionBridge... is connected" message and trust-store-password
> parameter.
> The problem is in
> org.apache.activemq.artemis.api.core.TransportConfiguration.toString(),
> particularly in condition
> if (key.equals(TransportConstants.KEYSTORE_PASSWORD_PROP_NAME) ||
> key.equals(TransportConstants.DEFAULT_TRUSTSTORE_PASSWORD))
--
This message was sent by Atlassian JIRA
(v6.3.4#6332)