RFR: 8283093: JMX connections should default to using an ObjectInputFilter
Daniel Fuchs
dfuchs at openjdk.org
Fri Sep 30 15:15:21 UTC 2022
On Fri, 30 Sep 2022 11:00:28 GMT, Kevin Walls <kevinw at openjdk.org> wrote:
> Set the management.properties "com.sun.management.jmxremote.serial.filter.pattern" value by default, to restrict types that can be deserialized.
>
> Use the example value from the Core Libraries guide (see section 2. Serialization Filtering / Built-in Filters / Filters for JMX), plus Subject which is needed when using authentication.
>
> The sun/management tests run OK with this change. The existing test sun/management/jmxremote/startstop/JMXStartStopTest.java will fail if the filter specified is made too restrictive.
Hi Kevin - have you tried connecting with jconsole to a java program (you can e.g. connect jconsole to itself) and verified that all looked OK and that there wasn't any exception logged while clicking through the various MBeans it exposes?
-------------
PR: https://git.openjdk.org/jdk/pull/10507
More information about the serviceability-dev
mailing list