[ https://issues.apache.org/jira/browse/SOLR-13985?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16989094#comment-16989094 ]
David Smiley commented on SOLR-13985: ------------------------------------- I'm +1 to the proposal but I doubt the patch is ready. Solr should maybe do an extra log from bin/solr if the default bind of localhost isused to alert users to this, who may not be used to it. Maybe bin/solr should have a convenient option to bind to something else. There should be an env variable to set this. And lastly as you mentioned -- docs, particularly the Solr Ref Guide. I do wonder if there are popular Solr deployment patterns used in which the traffic _appears_ to come from localhost when it's actually not. It would be good to know these; maybe mention in the documentation. > bind to localhost by default > ---------------------------- > > Key: SOLR-13985 > URL: https://issues.apache.org/jira/browse/SOLR-13985 > Project: Solr > Issue Type: Improvement > Security Level: Public(Default Security Level. Issues are Public) > Reporter: Robert Muir > Priority: Major > Attachments: SOLR-13985.patch > > > Currently solr binds to all interfaces by default. > The default should be safer, so that e.g. the user is not exposed to the > internet until they make an explicit step to do so. -- This message was sent by Atlassian Jira (v8.3.4#803005) --------------------------------------------------------------------- To unsubscribe, e-mail: issues-unsubscr...@lucene.apache.org For additional commands, e-mail: issues-h...@lucene.apache.org