[ 
https://issues.apache.org/jira/browse/SOLR-13985?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16989094#comment-16989094
 ] 

David Smiley commented on SOLR-13985:
-------------------------------------

I'm +1 to the proposal but I doubt the patch is ready.  Solr should maybe do an 
extra log from bin/solr if the default bind of localhost isused to alert users 
to this, who may not be used to it.  Maybe bin/solr should have a convenient 
option to bind to something else.  There should be an env variable to set this. 
 And lastly as you mentioned -- docs, particularly the Solr Ref Guide.

I do wonder if there are popular Solr deployment patterns used in which the 
traffic _appears_ to come from localhost when it's actually not.  It would be 
good to know these; maybe mention in the documentation.

> bind to localhost by default
> ----------------------------
>
>                 Key: SOLR-13985
>                 URL: https://issues.apache.org/jira/browse/SOLR-13985
>             Project: Solr
>          Issue Type: Improvement
>      Security Level: Public(Default Security Level. Issues are Public) 
>            Reporter: Robert Muir
>            Priority: Major
>         Attachments: SOLR-13985.patch
>
>
> Currently solr binds to all interfaces by default. 
> The default should be safer, so that e.g. the user is not exposed to the 
> internet until they make an explicit step to do so.



--
This message was sent by Atlassian Jira
(v8.3.4#803005)

---------------------------------------------------------------------
To unsubscribe, e-mail: issues-unsubscr...@lucene.apache.org
For additional commands, e-mail: issues-h...@lucene.apache.org

Reply via email to