[JBoss JIRA] (ELY-33) Identity Loading
by Darran Lofthouse (JIRA)
[ https://issues.jboss.org/browse/ELY-33?page=com.atlassian.jira.plugin.sys... ]
Darran Lofthouse reassigned ELY-33:
-----------------------------------
Assignee: Darran Lofthouse
> Identity Loading
> ----------------
>
> Key: ELY-33
> URL: https://issues.jboss.org/browse/ELY-33
> Project: WildFly Elytron
> Issue Type: Task
> Components: API / SPI
> Reporter: Darran Lofthouse
> Assignee: Darran Lofthouse
> Fix For: 1.0.0.Alpha3
>
>
> We currently have identity loading tied into the realm with the 'createSecurityIdentity' call, a couple of things to think about.
> Security identity loading can be tied to realm impl or could be separate, identity loading could be common to many realms - maybe a subsystem concern rather than core of Elytron but just raising here for further consideration.
--
This message was sent by Atlassian JIRA
(v6.3.15#6346)
10 years, 9 months
[JBoss JIRA] (ELY-33) Identity Loading
by Darran Lofthouse (JIRA)
[ https://issues.jboss.org/browse/ELY-33?page=com.atlassian.jira.plugin.sys... ]
Darran Lofthouse resolved ELY-33.
---------------------------------
Resolution: Out of Date
The APIs have evolved quite a bit in this area, we will address further issues as they arise.
> Identity Loading
> ----------------
>
> Key: ELY-33
> URL: https://issues.jboss.org/browse/ELY-33
> Project: WildFly Elytron
> Issue Type: Task
> Components: API / SPI
> Reporter: Darran Lofthouse
> Assignee: Darran Lofthouse
> Fix For: 1.0.0.Alpha3
>
>
> We currently have identity loading tied into the realm with the 'createSecurityIdentity' call, a couple of things to think about.
> Security identity loading can be tied to realm impl or could be separate, identity loading could be common to many realms - maybe a subsystem concern rather than core of Elytron but just raising here for further consideration.
--
This message was sent by Atlassian JIRA
(v6.3.15#6346)
10 years, 9 months
[JBoss JIRA] (ELY-175) SASL mechanism availability should take into account credential support.
by Darran Lofthouse (JIRA)
[ https://issues.jboss.org/browse/ELY-175?page=com.atlassian.jira.plugin.sy... ]
Darran Lofthouse resolved ELY-175.
----------------------------------
Resolution: Done
> SASL mechanism availability should take into account credential support.
> ------------------------------------------------------------------------
>
> Key: ELY-175
> URL: https://issues.jboss.org/browse/ELY-175
> Project: WildFly Elytron
> Issue Type: Feature Request
> Components: SASL
> Reporter: Darran Lofthouse
> Assignee: David Lloyd
> Fix For: 1.0.0.Alpha3
>
>
> One of the main reasons for having a getCredentialSupport API is so that we select appropriate authentication mechanisms based on the credentials available to us or the level of validation possible.
> This should also consider advertising all variants of a mechanism or strongest only.
> I will mention it here but we may want as a separate task some form of downgrade detection as this could be a sign of a malicious MITM.
--
This message was sent by Atlassian JIRA
(v6.3.15#6346)
10 years, 9 months
[JBoss JIRA] (ELY-175) SASL mechanism availability should take into account credential support.
by Darran Lofthouse (JIRA)
[ https://issues.jboss.org/browse/ELY-175?page=com.atlassian.jira.plugin.sy... ]
Darran Lofthouse reassigned ELY-175:
------------------------------------
Assignee: David Lloyd
> SASL mechanism availability should take into account credential support.
> ------------------------------------------------------------------------
>
> Key: ELY-175
> URL: https://issues.jboss.org/browse/ELY-175
> Project: WildFly Elytron
> Issue Type: Feature Request
> Components: SASL
> Reporter: Darran Lofthouse
> Assignee: David Lloyd
> Fix For: 1.0.0.Alpha3
>
>
> One of the main reasons for having a getCredentialSupport API is so that we select appropriate authentication mechanisms based on the credentials available to us or the level of validation possible.
> This should also consider advertising all variants of a mechanism or strongest only.
> I will mention it here but we may want as a separate task some form of downgrade detection as this could be a sign of a malicious MITM.
--
This message was sent by Atlassian JIRA
(v6.3.15#6346)
10 years, 9 months