<?xml version="1.0" encoding="UTF-8"?>











<rss version="2.0" xmlns:jf="http://www.jivesoftware.com/xmlns/jiveforums/rss">



<channel>
    <title>Support Forums: Message List - Security Managers: do you use them? For what?</title>
    <link>http://www.theserverside.com</link>
    <description>Most recent forum messages</description>
    <language>en</language>
    
        <generator>Jive Forums Silver 5.5.30 (www.jivesoftware.com)</generator>
    
    <pubDate>Fri, 24 May 2013 20:18:31 -0400</pubDate>


    <item>

        <title>Customers know about SecurityManager? I doubt it</title>
        <link>http://www.theserverside.com/discussions/thread.tss?thread_id=41920</link>

        

        
            <description><![CDATA[Come on. Besides, even if this is true (prove it), what does enabling the SecurityManager do for you if you don't have any policy defined? It's useless.]]></description>
        

        <pubDate>Wed, 30 Aug 2006 00:55:07 -0400</pubDate>

        

        <jf:creationDate>Wed, 30 Aug 2006 00:55:07 -0400</jf:creationDate>
        <jf:modificationDate>Wed, 30 Aug 2006 00:55:07 -0400</jf:modificationDate>
        <jf:date>Aug 30, 2006</jf:date>
        <jf:author>Scott Stirling</jf:author>
        <jf:replyCount>0</jf:replyCount>
    </item>


    <item>

        <title>Re: SecurityManager can be useful; most app servers don't enable it</title>
        <link>http://www.theserverside.com/discussions/thread.tss?thread_id=41920</link>

        

        
            <description><![CDATA[<blockquote>Enabling the Java SecurityManager and enforcing any kind of security policy can incur serious performance overhead as the JVM suddenly has to check all method invocations for permissions.<br><br>However, enabling the SecurityManager and...]]></description>
        

        <pubDate>Tue, 29 Aug 2006 03:15:49 -0400</pubDate>

        

        <jf:creationDate>Tue, 29 Aug 2006 03:15:49 -0400</jf:creationDate>
        <jf:modificationDate>Tue, 29 Aug 2006 03:15:49 -0400</jf:modificationDate>
        <jf:date>Aug 29, 2006</jf:date>
        <jf:author>John Brand</jf:author>
        <jf:replyCount>1</jf:replyCount>
    </item>


    <item>

        <title>SecurityManager can be useful; most app servers don't enable it</title>
        <link>http://www.theserverside.com/discussions/thread.tss?thread_id=41920</link>

        

        
            <description><![CDATA[Everyone here should know of the long-standing EJB spec restrictions on actions such as writing to the file system or starting a Thread in an EJB. But also know that most app servers never enforced these limitations. I do remember working with ISP...]]></description>
        

        <pubDate>Mon, 28 Aug 2006 13:44:10 -0400</pubDate>

        

        <jf:creationDate>Mon, 28 Aug 2006 13:44:10 -0400</jf:creationDate>
        <jf:modificationDate>Mon, 28 Aug 2006 13:44:10 -0400</jf:modificationDate>
        <jf:date>Aug 28, 2006</jf:date>
        <jf:author>Scott Stirling</jf:author>
        <jf:replyCount>2</jf:replyCount>
    </item>


    <item>

        <title>Security Manager : A Bane</title>
        <link>http://www.theserverside.com/discussions/thread.tss?thread_id=41920</link>

        

        
            <description><![CDATA[While developing a tapestry based application on Sun Platform( We used SUN JES Application server) we had to tweak a lot of code to get around the java security model. Tapestry uses class enhancements a lot and there is no way one can give permissions to...]]></description>
        

        <pubDate>Mon, 28 Aug 2006 12:35:52 -0400</pubDate>

        

        <jf:creationDate>Mon, 28 Aug 2006 12:35:52 -0400</jf:creationDate>
        <jf:modificationDate>Mon, 28 Aug 2006 12:35:52 -0400</jf:modificationDate>
        <jf:date>Aug 28, 2006</jf:date>
        <jf:author>Surjendu Kuila</jf:author>
        <jf:replyCount>0</jf:replyCount>
    </item>


    <item>

        <title>Re: Security Managers: do you use them? For what?</title>
        <link>http://www.theserverside.com/discussions/thread.tss?thread_id=41920</link>

        

        
            <description><![CDATA[<blockquote>Yeah, and the IT department at your customer company, which just invested $X millions in a state of the art WebSphere cluster with HA can just go screw themselfes?</blockquote>The clients we have all do not use an application server. They...]]></description>
        

        <pubDate>Mon, 28 Aug 2006 06:07:38 -0400</pubDate>

        

        <jf:creationDate>Mon, 28 Aug 2006 06:07:38 -0400</jf:creationDate>
        <jf:modificationDate>Mon, 28 Aug 2006 06:07:38 -0400</jf:modificationDate>
        <jf:date>Aug 28, 2006</jf:date>
        <jf:author>Ivo Limmen</jf:author>
        <jf:replyCount>0</jf:replyCount>
    </item>


    <item>

        <title>security manager</title>
        <link>http://www.theserverside.com/discussions/thread.tss?thread_id=41920</link>

        

        
            <description><![CDATA[<blockquote>Which servers have you deployed to that enable the security manager? What issues did you find through this, if any, and how did you work around them? Do you think simple removal of the security manager is an acceptable...]]></description>
        

        <pubDate>Mon, 28 Aug 2006 06:03:21 -0400</pubDate>

        

        <jf:creationDate>Mon, 28 Aug 2006 06:03:21 -0400</jf:creationDate>
        <jf:modificationDate>Mon, 28 Aug 2006 06:03:21 -0400</jf:modificationDate>
        <jf:date>Aug 28, 2006</jf:date>
        <jf:author>Maris Orbidans</jf:author>
        <jf:replyCount>0</jf:replyCount>
    </item>


    <item>

        <title>Re: Security Managers: do you use them? For what?</title>
        <link>http://www.theserverside.com/discussions/thread.tss?thread_id=41920</link>

        

        
            <description><![CDATA[<blockquote>I never even build an application that uses a application server (even though I consider myself an enterprise developer). If I would build one I would simply demand full control of the application server and that it is only used by our...]]></description>
        

        <pubDate>Mon, 28 Aug 2006 05:21:56 -0400</pubDate>

        

        <jf:creationDate>Mon, 28 Aug 2006 05:21:56 -0400</jf:creationDate>
        <jf:modificationDate>Mon, 28 Aug 2006 05:21:56 -0400</jf:modificationDate>
        <jf:date>Aug 28, 2006</jf:date>
        <jf:author>John Brand</jf:author>
        <jf:replyCount>1</jf:replyCount>
    </item>


    <item>

        <title>Re: Security Managers: do you use them? For what?</title>
        <link>http://www.theserverside.com/discussions/thread.tss?thread_id=41920</link>

        

        
            <description><![CDATA[When the codes running on your computer is not written by you, a SecurityManager is certainly needed. This includes applets on clients' machines and server apps running on an ASP's server written by its customers....]]></description>
        

        <pubDate>Mon, 28 Aug 2006 04:45:02 -0400</pubDate>

        

        <jf:creationDate>Mon, 28 Aug 2006 04:45:02 -0400</jf:creationDate>
        <jf:modificationDate>Mon, 28 Aug 2006 04:45:02 -0400</jf:modificationDate>
        <jf:date>Aug 28, 2006</jf:date>
        <jf:author>Cary Collins</jf:author>
        <jf:replyCount>0</jf:replyCount>
    </item>


    <item>

        <title>Re: Security Managers: do you use them? For what?</title>
        <link>http://www.theserverside.com/discussions/thread.tss?thread_id=41920</link>

        

        
            <description><![CDATA[<blockquote>Different requirements =&gt; different solutions.<br><br>If an application server is running only one<br>application (in a wide sense of the word - not necesarry<br>only one ear), then security manager is not so usefull.<br><br>If an...]]></description>
        

        <pubDate>Sun, 27 Aug 2006 03:17:24 -0400</pubDate>

        

        <jf:creationDate>Sun, 27 Aug 2006 03:17:24 -0400</jf:creationDate>
        <jf:modificationDate>Sun, 27 Aug 2006 03:17:24 -0400</jf:modificationDate>
        <jf:date>Aug 27, 2006</jf:date>
        <jf:author>Dan Creswell</jf:author>
        <jf:replyCount>1</jf:replyCount>
    </item>


    <item>

        <title>Re: Security Managers: do you use them? For what?</title>
        <link>http://www.theserverside.com/discussions/thread.tss?thread_id=41920</link>

        

        
            <description><![CDATA[Different requirements =&gt; different solutions....]]></description>
        

        <pubDate>Sat, 26 Aug 2006 21:57:04 -0400</pubDate>

        

        <jf:creationDate>Sat, 26 Aug 2006 21:57:04 -0400</jf:creationDate>
        <jf:modificationDate>Sat, 26 Aug 2006 21:57:04 -0400</jf:modificationDate>
        <jf:date>Aug 26, 2006</jf:date>
        <jf:author>Arne Vajh??j</jf:author>
        <jf:replyCount>2</jf:replyCount>
    </item>


    <item>

        <title>Re: Security Managers: do you use them? For what?</title>
        <link>http://www.theserverside.com/discussions/thread.tss?thread_id=41920</link>

        

        
            <description><![CDATA[I have not heard of a vulnerability that required configuring other than default security policies.  Ted Neward in Effective Enterprise Java suggests turning on "platform security" (Item 62) should an attacker be able to edit and run JSPs.  I just have...]]></description>
        

        <pubDate>Sat, 26 Aug 2006 20:21:16 -0400</pubDate>

        

        <jf:creationDate>Sat, 26 Aug 2006 20:21:16 -0400</jf:creationDate>
        <jf:modificationDate>Sat, 26 Aug 2006 20:21:16 -0400</jf:modificationDate>
        <jf:date>Aug 26, 2006</jf:date>
        <jf:author>Andrew Clifford</jf:author>
        <jf:replyCount>0</jf:replyCount>
    </item>


    <item>

        <title>Re: Security Managers: do you use them? For what?</title>
        <link>http://www.theserverside.com/discussions/thread.tss?thread_id=41920</link>

        

        
            <description><![CDATA[Forgot to say, I use a security manager with Jini Services all the time simply because it's an essential (but small) part of providing a secure deployment....]]></description>
        

        <pubDate>Sat, 26 Aug 2006 13:16:53 -0400</pubDate>

        

        <jf:creationDate>Sat, 26 Aug 2006 13:16:53 -0400</jf:creationDate>
        <jf:modificationDate>Sat, 26 Aug 2006 13:16:53 -0400</jf:modificationDate>
        <jf:date>Aug 26, 2006</jf:date>
        <jf:author>Dan Creswell</jf:author>
        <jf:replyCount>0</jf:replyCount>
    </item>


    <item>

        <title>Re: Security Managers: do you use them? For what?</title>
        <link>http://www.theserverside.com/discussions/thread.tss?thread_id=41920</link>

        

        
            <description><![CDATA[<blockquote>...<br>Security managers are sometimes very annoying in development, so annoying that Glassfish - the Java EE reference implementation - actually turned off the security manager by default.<br><br>While turning off the security manager makes...]]></description>
        

        <pubDate>Sat, 26 Aug 2006 13:09:47 -0400</pubDate>

        

        <jf:creationDate>Sat, 26 Aug 2006 13:09:47 -0400</jf:creationDate>
        <jf:modificationDate>Sat, 26 Aug 2006 13:09:47 -0400</jf:modificationDate>
        <jf:date>Aug 26, 2006</jf:date>
        <jf:author>Dan Creswell</jf:author>
        <jf:replyCount>0</jf:replyCount>
    </item>


    <item>

        <title>Re: Security Managers: do you use them? For what?</title>
        <link>http://www.theserverside.com/discussions/thread.tss?thread_id=41920</link>

        

        
            <description><![CDATA[No, I do not use security managers. It's a pain in the ass to use them. I never ever had any need for the use of them either. Security can be implemented on different levels and methods. You can even build them into the work process....]]></description>
        

        <pubDate>Sat, 26 Aug 2006 10:18:24 -0400</pubDate>

        

        <jf:creationDate>Sat, 26 Aug 2006 10:18:24 -0400</jf:creationDate>
        <jf:modificationDate>Sat, 26 Aug 2006 10:18:24 -0400</jf:modificationDate>
        <jf:date>Aug 26, 2006</jf:date>
        <jf:author>Ivo Limmen</jf:author>
        <jf:replyCount>3</jf:replyCount>
    </item>


    <item>

        <title>Security Managers: do you use them? For what?</title>
        <link>http://www.theserverside.com/discussions/thread.tss?thread_id=41920</link>

        

        
            <description><![CDATA[One of the features of Java from early in its design was its security model. Originally, it applied to applets, by isolating them into a sandbox, one that's generally been successful. However, with J2EE and JINI, the security manager constrains...]]></description>
        

        <pubDate>Sat, 26 Aug 2006 08:27:59 -0400</pubDate>

        

        <jf:creationDate>Sat, 26 Aug 2006 08:27:59 -0400</jf:creationDate>
        <jf:modificationDate>Sat, 26 Aug 2006 08:27:59 -0400</jf:modificationDate>
        <jf:date>Aug 26, 2006</jf:date>
        <jf:author>Joseph Ottinger</jf:author>
        <jf:replyCount>14</jf:replyCount>
    </item>



</channel>
</rss>

