[
https://issues.apache.org/jira/browse/GROOVY-12270?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18105460#comment-18105460
]
ASF GitHub Bot commented on GROOVY-12270:
-----------------------------------------
paulk-asert opened a new pull request, #2807:
URL: https://github.com/apache/groovy/pull/2807
… connector consumes
JmxBuilder's connectorServer documents properties:[authenticate:true,
passwordFile:..., accessFile:...], and wrote them into the connector
environment under com.sun.management.jmxremote.* names. Those names belong to
the JDK's out-of-the-box management agent, not to a connector server. The agent
reads them and translates them into the jmx.remote.x.* names the connector
actually consumes, then installs the authenticator itself; see
sun.management.jmxremote.ConnectorBootstrap. Nothing performed that translation
here, so an operator following the documented syntax started a connector with
no authenticator at all.
Verified rather than reasoned: with the environment this class built, the
connector reported no authenticator and a credential-less client connected and
read the MBean count; with jmx.remote.x.password.file the same client is
rejected with "Authentication failed! Credentials required".
Translate the aliases, and only when authentication was requested. Add
loginConfig for JAAS, mapping to jmx.remote.x.login.config. Reject
authenticate:true with no source of credentials at all, since that asks for
authentication and would otherwise start open, which is the failure being
fixed; a caller-supplied jmx.remote.authenticator counts as such a source,
since passing a JMXAuthenticator through is the standard JSR-160 route for
custom authentication.
The com.sun.management.jmxremote.* names remain accepted as input spellings
but are no longer copied into the environment, where they mean nothing; the ssl
alias is likewise consumed to select the socket factories rather than passed
through. Three GROOVY-12119 tests asserted the presence of those inert keys as
a witness that the environment map was not discarded; they now assert the
effective configuration instead, which is what their comments describe.
Note on urgency rather than severity: no released version has ever passed
the property map to the connector, because the building method returned null
until GROOVY-12119, which is in no GA release. There is therefore no installed
base of connectors that believe they are authenticated. What makes this worth
fixing before GA is that GROOVY-12119 leaves SSL working while authentication
silently does not, which is a quieter failure than the wholly broken
configuration it replaced.
The default remains an unauthenticated connector when no authentication is
requested. Warning on that is a separate question from this one.
> remove legacy JMX connector authentication names
> ------------------------------------------------
>
> Key: GROOVY-12270
> URL: https://issues.apache.org/jira/browse/GROOVY-12270
> Project: Groovy
> Issue Type: Improvement
> Reporter: Paul King
> Assignee: Paul King
> Priority: Major
>
--
This message was sent by Atlassian Jira
(v8.20.10#820010)