GT4 Java WS A&A Quality Report


1. Test coverage reports

2. Code analysis reports

3. Outstanding bugs

  • Bug 2362: location of user proxy for java inconsistencies
  • Bug 2445: Holder problem
  • Bug 2907 Secure Conversation (Encryption) does not provide any message level security for the SOAP headers
  • Bug 3027: Kerberos based authentication option for GT4
  • Bug 3171: add RFC 2253 principal name to JAAS subject
  • Bug 3449 ERROR container.GSIServiceThread
  • Bug 3603: Remotte exceptions thrown contain server specific information
  • Bug 3928: IPv6 addresses in reverse lookups - fix or faq?
  • Bug 3941: Expired credentials detected - candidate for sec error msg improvements
  • Bug 4222 Allow for credential refresh in subscriptions
  • Bug 4403Secure calls for secure context establishment
  • Bug 4442 Security descriptor refresh
  • Bug 5008 voms-proxy-init creates non-critical KeyUsage extension which causes Java GSI to raise exception
  • Bug 5026 Signarure validation failure on GRAM/RFT interaction on some cases

4. Bug Fixes

  • Bug 2535: <proxy-file> causes container to fail
  • Bug 2651: /dev/random vs. /dev/urandom
  • Bug 2743: grid-mapfile location should be in global security descriptor
  • Bug 2207: Missing security error 'timestampNotOk'
  • Bug 2651: /dev/random vs. /dev/urandom
  • Bug 2743: grid-mapfile location should be in global security descriptor
  • Bug 2899: relative path does not work for credentials in Security Descriptor
  • Bug 2900: Job submssion does not work using relative path in global_security_descriptor.xml and absolute path in sudoers.
  • Bug 2955: Job submission fails when container is started from non GLOBUS_LOCATION
  • Bug 2969: Too relaxed rules on DN comparisons (all versions of GT)
  • Bug 3849: Container descriptor is shared across containers in one JVM
  • Bug 3689 Possible royalty / patent issue with BouncyCastle jar IDEA Algorithm
  • Bug 3891: Public credentials of client in peer subject
  • Bug 3965: Credential refresh problems
  • Bug 4021: globus-start-container -containerDesc not working
  • Bug 4136: At least one of the headers used in dispatch was not secured error
  • Bug 4146: setting default container security via environment
  • Bug 4507: Problem with corrupted CRL
  • Bug 4535 Client security descriptor does not allow for GSI Transport configuration
  • Bug 4584: security descriptor uses operation field name instead of QName
  • Bug 4837: Username/password not working.
  • Bug 4846: Authorization framwork should preserve the order of attributes
  • Bug 4893: Improve ParameterPIP test
  • Bug 5076: Authorization interface declares serializable, but impls are not
  • Bug 5544: Interceptor initializes twice
  • Bug 5608: More details in security logging please
  • Bug 5756: allow developer to bypass secure msg consistency check
  • Bug 5757: allow developer to bypass sending cert chain in secure message

5. Performance reports

Secure access of WSRF and WSN operations using GSI Transport and GSI Secure Message have been measured. Test reports are in here.