JVM security properties warning

Sean Mullan sean.mullan at oracle.com
Tue Nov 28 15:52:14 UTC 2023


This should be discussed on the security-dev list, so let’s discuss and followup there. Bcc-ing idk-dev.

—Sean

On Nov 27, 2023, at 5:30 PM, Capasso, Autumn <autumcap at amazon.com<mailto:autumcap at amazon.com>> wrote:


Hi my name is Autumn Capasso, I am an Software engineer for the Amazon Corretto team. I am purposing to a mechanism to warn developers about misconfigure Security properties by mistaking them for system properties. We have found that customers are often confused by security properties they think are System properties. Developers think their changing a System property and not only do they not get their desired effect. I created a JBS issues that I have included in this email.
https://bugs.openjdk.org/browse/JDK-8320559


Thank you,
Autumn Capasso

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://mail.openjdk.org/pipermail/jdk-dev/attachments/20231128/a666ec61/attachment-0001.htm>


More information about the jdk-dev mailing list