Configure Global Security
Enable security
TCP port for JNLP agents > Fixed, Random, Disable
Disable remember me
Access Control
> Security Realm
- Delegate to servlet container > assets, cli, git, github-webhook, jnlpJars, subversion, whoAmI
- Jenkins' pwn user database > 사용자 가입 허용
- LDAP > ex)ldaps://server:port
- Unix user/group database > Service Name > Test
> Authorization
- Anyone can do anything
- Legacy mode
- Logged-in users can do anything > Allow anonymous read access
- Matrix-based security
- Project-based Matrix Authorization Stategy
Markup Formatter > Plain text, Safe HTML
Prevent Cross Site Request Firgery exploits
Crumbs
> Crumb Algorithm
- Default Crumb Issuer > Enable proxy compatibility
Plugin Manager
> Use browser for metadata download
> Enable Slave → Master Access Control