Why are the RunAs credentials always allowed to access the JBoss server without calling the login module?
Issue
- Why are the RunAs credentials always allowed to access the JBoss server without calling the login module?
- One consequence is that our production environment can be accessed from any non-production server simply be using a RunAs role. I think this is a major security problem. Do you have any comments on this?
Environment
- JBoss Enterprise Application Platform
- 4.x
- 5.x
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase of over 48,000 articles and solutions.
Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.
