]
Jiri Ondrusek moved JBEAP-15039 to WFCORE-3963:
-----------------------------------------------
Project: WildFly Core (was: JBoss Enterprise Application Platform)
Key: WFCORE-3963 (was: JBEAP-15039)
Workflow: GIT Pull Request workflow (was: CDW with loose statuses v1)
Component/s: Security
(was: Security)
Affects Version/s: 6.0.0.Alpha3
(was: 7.1.1.GA)
Fix Version/s: (was: 7.1.5.GA)
[GSS] (7.1.z) anonymous authentication for ejbs using legacy
configuration - test
----------------------------------------------------------------------------------
Key: WFCORE-3963
URL:
https://issues.jboss.org/browse/WFCORE-3963
Project: WildFly Core
Issue Type: Bug
Components: Security
Affects Versions: 6.0.0.Alpha3
Reporter: Jiri Ondrusek
Assignee: Bartosz Spyrko-Ĺmietanko
Labels: Regression, test
Anonymous authentication for ejbs works on EAP 7.0.x using the following configuration:
<subsystem xmlns="urn:jboss:domain:remoting:4.0">
<endpoint/>
<http-connector name="http-remoting-connector"
connector-ref="default" security-realm="ApplicationRealm">
<properties>
<property name="SASL_MECHANISMS"
value="ANONYMOUS,PLAIN"/>
<property name="SASL_POLICY_NOANONYMOUS"
value="false"/>
</properties>
</http-connector>
</subsystem>
Unfortunately, this same configuration does not work on 7.1.1. It looks
like the server still wants to use DIGEST-MD5 based authentication.
Has the legacy based configuration (non-elytron) for anonymous ejb
access changed on eap 7.1.1?
I am attaching the standalone.xml, server.log and client log.
Customer does not want to use elytron at the moment.