Re: SecurityManager

Tim Blackman <[email protected]> Fri, 19 Dec 2008 07:43:45 -0500
Newsgroups gmane.comp.java.sun.rmi
Message-ID <[email protected]>
On Dec 18, 2008, at 4:55 PM, Gregg Wonderly wrote:

> Surendra Lingareddy wrote:
>> Thanks Greg. Security is quite critical and thus we went the SSL and
>> Certs route. For now, I do have a SecurityManager(SM) in place with  
>> a policyfile that
>> sets the flag to 'AllPermissions'. That seems equally bad and mucking
>> with it seems to create more problems. My team tried a few controlled
>> edits of the policyfile to provide disk r/w/ex access but clients  
>> do not
>> seem to make a successful connection to the server when we restrict
>> certain IP and port access.
>> I understand that a SecurityManager is needed when you build a  
>> generic
>> service. SM checks and provides the stubs to the clients at run-time.
>> But, if you do distribute the stubs as compiled classes, and if the  
>> only
>> way a client can connect to the server is via SSL, then I fail to see
>> the advantage SM brings into the picture.
>> I would rather not provide one at all than having a policyfile that
>> allows 'allpermissions'.
>
> The predominate issue that I always encounter is the "hidden"  
> security checks that are not visible.  Things like property value  
> checks etc. can really be frustrating to work through.  I don't  
> recall whether it's still visible somewhere or not, but the guys at  
> Sun, on the Jini team, had a SecurityManager that you could install,  
> which would accumulate all the permission checks made, and then dump  
> them out so that you could run an application and get a "default"  
> policy file pretty easily.  I don't know if that's still around or  
> not.  Perhaps Peter knows?

Actually, it is a security Policy rather than a SecurityManager.

The class is called com.sun.jini.tool.DebugDynamicPolicyProvider, and  
is available as part of the Apache River 2.1.1 release -- see:

   http://incubator.apache.org/river/RIVER/downloads.html

- Tim

===========================================================================
To unsubscribe, send email to [email protected] and include in the body
of the message "signoff RMI-USERS".  For general help, send email to
[email protected] and include in the body of the message "help".

For a list of frequently asked RMI questions please refer to:
http://java.sun.com/j2se/1.3/docs/guide/rmi/faq.html

To view past RMI-USERS postings, please see:
http://archives.java.sun.com/archives/rmi-users.html