Skip to content

[MNG-8372] [WARNING] Legacy/insecurely encrypted password detected for server - what can/shall I do about it? #9481

@jira-importer

Description

@jira-importer

Philipp Ottlinger opened MNG-8372 and commented

I ran into above error message and asked myself what to do ....
the error message does not tell me anything.

https://maven.apache.org/guides/mini/guide-encryption.html
is the way I encrypted my password.

Can someone clarify the implication of this error message? Is there a page that tells me how to properly/safely configure my credentials. To my mind it would be helpful to have a before/after example to explicitly show where the problem is and how to circumvent it.

Thanks

$ ./mvnw
Apache Maven 4.0.0-beta-5 (6e78fcf)
Maven home: /home/me/.m2/wrapper/dists/apache-maven-4.0.0-beta-5/4431294f
Java version: 21.0.5, vendor: Oracle Corporation, runtime: /home/me/jdk-21.0.5
Default locale: de_DE, platform encoding: UTF-8
OS name: "linux", version: "5.15.0-125-generic", arch: "amd64", family: "unix"
[WARNING] Legacy/insecurely encrypted password detected for server srv.snapshots.https
[WARNING] Legacy/insecurely encrypted password detected for server srv.releases.https
[INFO] Scanning for projects...


Affects: 4.0.0-beta-5

Remote Links:

Backported to: 4.0.0-rc-1

1 votes, 2 watchers

Metadata

Metadata

Assignees

Labels

bugSomething isn't workingpriority:majorMajor loss of function

Type

No type

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions