[ 
https://issues.apache.org/jira/browse/GROOVY-12270?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18105460#comment-18105460
 ] 

ASF GitHub Bot commented on GROOVY-12270:
-----------------------------------------

paulk-asert opened a new pull request, #2807:
URL: https://github.com/apache/groovy/pull/2807

   … connector consumes
   
   JmxBuilder's connectorServer documents properties:[authenticate:true, 
passwordFile:..., accessFile:...], and wrote them into the connector 
environment under com.sun.management.jmxremote.* names. Those names belong to 
the JDK's out-of-the-box management agent, not to a connector server. The agent 
reads them and translates them into the jmx.remote.x.* names the connector 
actually consumes, then installs the authenticator itself; see 
sun.management.jmxremote.ConnectorBootstrap. Nothing performed that translation 
here, so an operator following the documented syntax started a connector with 
no authenticator at all.
   
   Verified rather than reasoned: with the environment this class built, the 
connector reported no authenticator and a credential-less client connected and 
read the MBean count; with jmx.remote.x.password.file the same client is 
rejected with "Authentication failed! Credentials required".
   
   Translate the aliases, and only when authentication was requested. Add 
loginConfig for JAAS, mapping to jmx.remote.x.login.config. Reject 
authenticate:true with no source of credentials at all, since that asks for 
authentication and would otherwise start open, which is the failure being 
fixed; a caller-supplied jmx.remote.authenticator counts as such a source, 
since passing a JMXAuthenticator through is the standard JSR-160 route for 
custom authentication.
   
   The com.sun.management.jmxremote.* names remain accepted as input spellings 
but are no longer copied into the environment, where they mean nothing; the ssl 
alias is likewise consumed to select the socket factories rather than passed 
through. Three GROOVY-12119 tests asserted the presence of those inert keys as 
a witness that the environment map was not discarded; they now assert the 
effective configuration instead, which is what their comments describe.
   
   Note on urgency rather than severity: no released version has ever passed 
the property map to the connector, because the building method returned null 
until GROOVY-12119, which is in no GA release. There is therefore no installed 
base of connectors that believe they are authenticated. What makes this worth 
fixing before GA is that GROOVY-12119 leaves SSL working while authentication 
silently does not, which is a quieter failure than the wholly broken 
configuration it replaced.
   
   The default remains an unauthenticated connector when no authentication is 
requested. Warning on that is a separate question from this one.




> remove legacy JMX connector authentication names
> ------------------------------------------------
>
>                 Key: GROOVY-12270
>                 URL: https://issues.apache.org/jira/browse/GROOVY-12270
>             Project: Groovy
>          Issue Type: Improvement
>            Reporter: Paul King
>            Assignee: Paul King
>            Priority: Major
>




--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to