Bug 777676 (SOA-188) - Out of the box jUDDI should not be used for production
Summary: Out of the box jUDDI should not be used for production
Keywords:
Status: CLOSED NEXTRELEASE
Alias: SOA-188
Product: JBoss Enterprise SOA Platform 4
Classification: JBoss
Component: Documentation
Version: 4.2 IR7
Hardware: Unspecified
OS: Unspecified
high
high
Target Milestone: ---
: 4.2 CR3
Assignee: Joshua Wulf
QA Contact:
URL: http://jira.jboss.org/jira/browse/SOA...
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2007-11-28 18:32 UTC by Len DiMaggio
Modified: 2014-10-19 22:59 UTC (History)
1 user (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2007-12-12 15:20:30 UTC
Type: Bug


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Issue Tracker SOA-188 0 None None None Never

Description Len DiMaggio 2007-11-28 18:32:35 UTC
project_key: SOA

Out of the box jUDDI should not be used for production

Description of problem:

The out-of-the-box registry is insecure - it can inspected by anyone. This is a known condition the out of the box UDDI registry is based on Apache jUDDI and Scout. We do not recommend people to use jUDDI (in production) just as we do not recommend people to use HSQLDB in production.

This needs to be be made clear in the SOA-P docs. 

Also - the index.html file (server/*/deploy/juddi-service.sar/juddi.war/index.html) - http://hostname:8080/juddi/ displays this text:

===========================
Welcome to JBoss JUDDI
This webapp accepts POST requests to:
/inquiry
/publish
===========================

I'd recommend removing this text - it just makes it more obvious.

Version-Release number of selected component (IR or RC #, component ver)
soa-4.2.0-IR7.0.zip
standalone-soa-4.2.0-IR7.0.zip

How reproducible:
100%

Steps to Reproduce:
1. Startup the server - access juddi

Actual results:
Registry can be inspected.

Expected results:

Additional info: (e.g., stack trace)

Attachments (e.g., server log)

Comment 1 Len DiMaggio 2007-12-12 15:20:30 UTC
Closing this JIRA per the discussion at the Dec 11 SOA-P meeting.


Note You need to log in before you can comment on or make changes to this bug.