<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Securing your JBoss JMX Invoker Layer</title>
	<atom:link href="http://objectopia.com/2009/10/01/securing-jmx-invoker-layer-in-jboss/feed/" rel="self" type="application/rss+xml" />
	<link>http://objectopia.com/2009/10/01/securing-jmx-invoker-layer-in-jboss/</link>
	<description></description>
	<lastBuildDate>Tue, 06 Dec 2011 08:48:38 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: Technical Related Notes &#187; Blog Archive &#187; links for 2011-03-22</title>
		<link>http://objectopia.com/2009/10/01/securing-jmx-invoker-layer-in-jboss/#comment-110</link>
		<dc:creator><![CDATA[Technical Related Notes &#187; Blog Archive &#187; links for 2011-03-22]]></dc:creator>
		<pubDate>Mon, 18 Apr 2011 09:59:19 +0000</pubDate>
		<guid isPermaLink="false">http://objectopia.com/?p=154#comment-110</guid>
		<description><![CDATA[[...] secure jboss (tags: jboss) [...]]]></description>
		<content:encoded><![CDATA[<p>[...] secure jboss (tags: jboss) [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Slava</title>
		<link>http://objectopia.com/2009/10/01/securing-jmx-invoker-layer-in-jboss/#comment-77</link>
		<dc:creator><![CDATA[Slava]]></dc:creator>
		<pubDate>Sun, 03 Apr 2011 04:34:03 +0000</pubDate>
		<guid isPermaLink="false">http://objectopia.com/?p=154#comment-77</guid>
		<description><![CDATA[for those who find this topic by search:

There is a community courtesy notification for a severe security issue affecting some of the JBoss projects and products. Default security settings in web.xml protect only GET and POST protocols leaving another ones open. Please refer to the following Red Hat KBase article for more information:
 
&lt;a href=&quot;http://kbase.redhat.com/faq/docs/DOC-30741&quot; rel=&quot;nofollow&quot;&gt;JBoss Products &amp; CVE-2010-0738&lt;/a&gt;
 
Only when you apply the solution you can be sure that your JMX Console is protected.
Please note that Web Console has the same issue, and you need to apply the solution to it as well.

Also it is recommended to hash passwords in the config files. Read about how to do it in &lt;a href=&quot;http://docs.jboss.org/jbossas/getting_started/v2/startguide40/security.html&quot; rel=&quot;nofollow&quot;&gt;JBoss Getting Started guide&lt;/a&gt;.]]></description>
		<content:encoded><![CDATA[<p>for those who find this topic by search:</p>
<p>There is a community courtesy notification for a severe security issue affecting some of the JBoss projects and products. Default security settings in web.xml protect only GET and POST protocols leaving another ones open. Please refer to the following Red Hat KBase article for more information:</p>
<p><a href="http://kbase.redhat.com/faq/docs/DOC-30741" rel="nofollow">JBoss Products &amp; CVE-2010-0738</a></p>
<p>Only when you apply the solution you can be sure that your JMX Console is protected.<br />
Please note that Web Console has the same issue, and you need to apply the solution to it as well.</p>
<p>Also it is recommended to hash passwords in the config files. Read about how to do it in <a href="http://docs.jboss.org/jbossas/getting_started/v2/startguide40/security.html" rel="nofollow">JBoss Getting Started guide</a>.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jon Court</title>
		<link>http://objectopia.com/2009/10/01/securing-jmx-invoker-layer-in-jboss/#comment-46</link>
		<dc:creator><![CDATA[Jon Court]]></dc:creator>
		<pubDate>Sun, 28 Feb 2010 00:22:19 +0000</pubDate>
		<guid isPermaLink="false">http://objectopia.com/?p=154#comment-46</guid>
		<description><![CDATA[Nice - thanks for picking this up Gilles,

I had meant to contribute this back actually - somehow it dropped off my radar.

Regards,
Jon]]></description>
		<content:encoded><![CDATA[<p>Nice &#8211; thanks for picking this up Gilles,</p>
<p>I had meant to contribute this back actually &#8211; somehow it dropped off my radar.</p>
<p>Regards,<br />
Jon</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gilles</title>
		<link>http://objectopia.com/2009/10/01/securing-jmx-invoker-layer-in-jboss/#comment-45</link>
		<dc:creator><![CDATA[Gilles]]></dc:creator>
		<pubDate>Sun, 28 Feb 2010 00:09:33 +0000</pubDate>
		<guid isPermaLink="false">http://objectopia.com/?p=154#comment-45</guid>
		<description><![CDATA[This feature will be added to twiddle in next JBoss releases
https://jira.jboss.org/jira/browse/JBPAPP-3391]]></description>
		<content:encoded><![CDATA[<p>This feature will be added to twiddle in next JBoss releases<br />
<a href="https://jira.jboss.org/jira/browse/JBPAPP-3391" rel="nofollow">https://jira.jboss.org/jira/browse/JBPAPP-3391</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>

