Jini(TM) Technology Starter Kit v2.0.2 now available
Bob Scheifler <[email protected]>
| Newsgroups | gmane.comp.java.sun.javaspaces |
|---|---|
| Message-ID | <[email protected]> |
We are pleased to announce general availability of the Jini(TM)
Technology Starter Kit, version 2.0.2. The primary purpose of this
release is to fix several security issues that exist in previous
releases of the starter kit.
This release is licensed under the Apache License Version 2.0, and is
available for download here:
http://starterkit.jini.org/
This release incorporates fixes to several significant security issues
that exist in the v2.0, v2.0_001, v2.0_002, v2.0.1, and v2.1Beta
releases of the starter kit. The nature of these issues is such that,
in certain circumstances, with those releases, downloaded code can
acquire new permissions not intentionally granted to it, and can cause
remote calls to be made that expose authenticated and possibly
delegated identities to remote hosts without having been granted
permission to do so.
We strongly recommend that you upgrade to this release if you are
using any of the production releases cited above in a secure
deployment in which untrusted objects from an attacker could
potentially be downloaded into a VM with any of the following
characteristics:
- permissions are dynamically granted to trusted downloaded code, and
untrusted code could cause harm if it acquired those same
permissions
- code is executed with Subjects containing credentials that support
delegation in remote calls (in particular, Kerberos credentials when
forwardable tickets are enabled)
- code is executed with Subjects containing credentials that support
authentication in remote calls, but client anonymity in remote calls
is sometimes important
The fixes incorporated into this release do not conform to certain
aspects of existing Jini Community(SM) Standards. However, we do not
expect these fixes to cause any problems in existing deployments. If a
problem does arise, we have provided system properties that can be set
to restore some compatible semantics, at the risk of reintroducing
some of the security issues; see the release notes for information.
We will be proposing revised specifications for the affected Standards
to the Jini Community as additional Porter proposals, along with more
detailed explanations of the security issues, after first allowing
some time for people to upgrade to this release. Until then, we
prefer to avoid public discussion of how these issues could be
exploited, but we welcome direct email if you have questions about the
ramifications for your secure deployments.
Due to issues relating to the transition in licensing, this release
does not include the pro.zip file that is necessary to run persistent
configurations of Outrigger. (All of the classes necessary to run
transient configurations of Outrigger are provided.) We are sorry for
any inconvenience this will cause and hope to resolve this issue in
the future.
- Bob
===========================================================================
To unsubscribe, send email to [email protected] and include in the body
of the message "signoff JAVASPACES-USERS". For general help, send email to
[email protected] and include in the body of the message "help".
To view past JAVASPACES-USERS postings, please see:
http://archives.java.sun.com/archives/javaspaces-users.html
JDC members can download the JavaSpaces(tm) Technology from:
http://developer.java.sun.com/developer/products/jini/