Skip to main content

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] [List Home]
Re: [cross-project-issues-dev] [Hudson] access to Hudson build configurations is public

Not sure about the internal Eclipse authentication infrastructure, but I am running 'our' Hudson build server behind a Apache webserver that does the SSL encryption, and the Hudson itself is using our LDAP to authorize users. Denis, I could send you a screenshot of my Hudson configuration if that helps to get started.

Markus



2009/3/11 Oisin Hurley <oisin.hurley@xxxxxxxxx>
> For what it's worth, Hudson was set up by (Rich Gronback? Adrian Skehill?)
> specifically for the Galileo build.  I'm a bit out of the loop, but it seems
> people are using it for much more than that.

I know - it works and we all piled on and constructed a favela out
of the available materials. Now we are demanding clean water and
sanitation ;-)

>Perhaps Rich, Adrian and/or
> other Hudson experts can chime in and configure it to be more secure?

If you try to create a new job, then you get asked to log in. If you go to
the home page, you get asked to log in. If you view a job, then hit
'configure' or 'build now' it doesn't ask you to log in. So I think we need
to start with requiring login for those capabilities (and of course things
like 'delete project', 'edit description', basically anything writable).

Maybe the most lightweight action to take now is let apache
do the securing [1]?

 --oh

[0] http://wiki.hudson-ci.org/display/HUDSON/Securing+Hudson
[1] http://wiki.hudson-ci.org/display/HUDSON/Apache+frontend+for+security
_______________________________________________
cross-project-issues-dev mailing list
cross-project-issues-dev@xxxxxxxxxxx
https://dev.eclipse.org/mailman/listinfo/cross-project-issues-dev



--
Markus Knauer
EclipseSource
###   phone: +49 721 664 733 0  (GMT +1)
###     fax: +49 721 664 733 29
###     web: www.eclipsesource.com

Innoopract Informationssysteme GmbH
Stephanienstrasse 20, 76133 Karlsruhe Germany
General Manager: Jochen Krause
Registered Office: Karlsruhe, Commercial Register Mannheim HRB 107883


Back to the top