[Mapguide-trac] [mapguide-trac] #2069: Maestro cannot create encrypted MG_USER_CREDENTIALS resource data

MapGuide Open Source trac_mapguide at osgeo.org
Tue Jul 10 07:44:28 PDT 2012


#2069: Maestro cannot create encrypted MG_USER_CREDENTIALS resource data
-----------------------+----------------------------------------------------
   Reporter:  jng      |       Owner:  jng                    
       Type:  defect   |      Status:  new                    
   Priority:  high     |   Milestone:  Maestro-4.0-maintenance
  Component:  Maestro  |     Version:                         
   Severity:  blocker  |    Keywords:                         
External_id:           |  
-----------------------+----------------------------------------------------
 Maestro has been creating feature sources with plaintext credentials since
 the very beginning.

 It turns out the secure alternative (with %MG_USERNAME% and %MG_PASSWORD%
 placeholders) currently is not possible because Maestro does not have the
 ability to encrypt the entered username/password into the
 MG_USER_CREDENTIALS resource data.

 There is major security implications in not being able to do this as
 Anonymous users can access such feature source. Denying repository read
 access breaks rendering/stylization for this user and is not an acceptable
 workaround.

-- 
Ticket URL: <http://trac.osgeo.org/mapguide/ticket/2069>
MapGuide Open Source <http://mapguide.osgeo.org/>
MapGuide Open Source Internals


More information about the mapguide-trac mailing list