[
http://jira.codehaus.org/browse/MNG-4611?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=216993#action_216993
]
Yoav Landman commented on MNG-4611:
-----------------------------------
If the password escape mechanism is broken, how is it not a bug? There is
really nothing "improper" about the password used, and it is currently the only
way to centrally enforce security and to have zero client-side password
generation or clear text keys on the client.
> 3.0-alpha7 password decryption log verbosity
> --------------------------------------------
>
> Key: MNG-4611
> URL: http://jira.codehaus.org/browse/MNG-4611
> Project: Maven 2 & 3
> Issue Type: Bug
> Reporter: Dale Wyttenbach
> Assignee: Benjamin Bentmann
>
> The log verbosity of password decryption in 3.0-alpha7 that makes the mvn -X
> option effectively unusable. The password I've got in my settings.xml file
> looks like this:
> <password>{DESede}y+qq...==</password>
> This is an Artifactory setup password and it does work, however mvn -X logs
> exceptions about it so frequently that it makes -X almost impossible to use.
> Is there some way I can suppress this behavior through configuration? The
> exception that it logs over and over again is:
> [DEBUG] Failed to decrypt password for server central:
> org.sonatype.plexus.components.cipher.PlexusCipherException:
> java.lang.ArrayIndexOutOfBoundsException
> org.sonatype.plexus.components.sec.dispatcher.SecDispatcherException:
> org.sonatype.plexus.components.cipher.PlexusCipherException:
> java.lang.ArrayIndexOutOfBoundsException
> ...
> Caused by: java.lang.ArrayIndexOutOfBoundsException
> at java.lang.System.arraycopy(Native Method)
> at
> org.sonatype.plexus.components.cipher.PBECipher.decrypt64(PBECipher.java:175)
> ... 47 more
--
This message is automatically generated by JIRA.
-
If you think it was sent incorrectly contact one of the administrators:
http://jira.codehaus.org/secure/Administrators.jspa
-
For more information on JIRA, see: http://www.atlassian.com/software/jira