Uploaded image for project: 'Sling'
  1. Sling
  2. SLING-11782

Document Sling threat model and how to properly secure Sling

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Open
    • Major
    • Resolution: Unresolved
    • None
    • None
    • Documentation, Site

    Description

      The documentation should be more explicit about to run sling in a secure way. In particular we should provide some information about the underlying threat model.

      For example we should be being explicit about the fact that whoever has access to the OSGi console has file system access with the privileges of the JRE.

      cc: rombert, cziegeler

      Attachments

        Activity

          People

            Unassigned Unassigned
            angela Angela Schreiber
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated: