Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1038397 - Role Based Access Control (RBAC) does not work with Java Security Manager (JSM) enabled
Role Based Access Control (RBAC) does not work with Java Security Manager (JS...
Status: CLOSED NOTABUG
Product: JBoss Enterprise Application Platform 6
Classification: JBoss
Component: Domain Management (Show other bugs)
6.2.0
Unspecified Unspecified
high Severity high
: GA
: EAP 6.3.0
Assigned To: Scott Mumford
Russell Dickenson
: Reopened
: 1035231 (view as bug list)
Depends On:
Blocks: 1036618 1040480
  Show dependency treegraph
 
Reported: 2013-12-04 23:10 EST by David Jorm
Modified: 2015-02-22 20:36 EST (History)
4 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
When JBoss EAP 6 was run with the Java Security Manager enabled, the Role-Based Access-Control system was effectively disabled because in this situation all authenticated users were treated as SuperUsers. The only way to use Role-Based Access-Control was without the Java Security Manager enabled. This issue was fixed in this release by making all access to the current `AccessControlContext` happen outside of the privileged action. As a result, Role-Based Access-Control is now still effective when enabling the Java Security Manager.
Story Points: ---
Clone Of:
Environment:
Last Closed: 2015-02-22 20:36:41 EST
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description David Jorm 2013-12-04 23:10:41 EST
Description of problem:

Please cover this in the release notes for EAP 6.2.0 GA.

When Red Hat JBoss EAP 6 is run with the Java Security Manager (JSM) enabled, the Role Based Access Control (RBAC) system is effectively disabled because in this situation all authenticated users are treated as SuperUsers. The only way to use RBAC currently is without the JSM enabled.
Comment 3 Scott Mumford 2014-07-16 20:03:21 EDT
*** Bug 1035231 has been marked as a duplicate of this bug. ***

Note You need to log in before you can comment on or make changes to this bug.