View Issue Details

IDProjectCategoryView StatusLast Update
000187410000-007: Profilespublic2012-03-02 17:08
ReporterJim Luth Assigned ToPaul Hunkar  
PrioritynormalSeveritymajorReproducibilityalways
Status closedResolutionfixed 
Product Version1.01 
Fixed in Version1.02 
Summary0001874: Secure by default
Description

The current (1.02 draft) makes it clear that anonymous user access must be disabled by default. We need to add a similar requirement for application level security, i.e. Security Policy NONE must not be allowed by default (if other security policies are supported).

TagsNo tags attached.
Commit Version
Fix Due Date

Activities

Paul Hunkar

2012-03-02 08:53

developer   ~0003344

Added text to indicate that this security policy should be disable by default if any other security policies are available

Jim Luth

2012-03-02 17:08

administrator   ~0003345

Reviewed and agreed in telecon.

Issue History

Date Modified Username Field Change
2012-02-10 17:48 Jim Luth New Issue
2012-02-13 09:48 Paul Hunkar Status new => assigned
2012-02-13 09:48 Paul Hunkar Assigned To => Paul Hunkar
2012-03-02 08:53 Paul Hunkar Status assigned => resolved
2012-03-02 08:53 Paul Hunkar Resolution open => fixed
2012-03-02 08:53 Paul Hunkar Note Added: 0003344
2012-03-02 17:08 Jim Luth Status resolved => closed
2012-03-02 17:08 Jim Luth Note Added: 0003345
2012-03-02 17:08 Jim Luth Fixed in Version => 1.02