]
Tomaz Cerar resolved WFLY-2980.
-------------------------------
Resolution: Cannot Reproduce Bug
TLS client authentication configuration not working
---------------------------------------------------
Key: WFLY-2980
URL:
https://issues.jboss.org/browse/WFLY-2980
Project: WildFly
Issue Type: Bug
Components: Web (Undertow)
Affects Versions: 8.0.0.Final
Reporter: dfisher
Assignee: Tomaz Cerar
Configuration of a security realm with a truststore does not result in an SSL trust
manager with the appropriate certificate authorities.
This configuration:
{code}
<security-realm name="HTTPSRealm">
<server-identities>
<ssl>
<keystore alias="server"
path="/path/to/my.keystore" keystore-password="changeit" />
</ssl>
</server-identities>
<authentication>
<truststore path="/path/to/my.truststore"
keystore-password="changeit" />
</authentication>
</security-realm>
{code}
Should expose the certificates in my.truststore as accepted authorities for client
authentication.
An SSL debug shows that no authorities are configured:
{code}
*** CertificateRequest
Cert Types: RSA, DSS, ECDSA
Cert Authorities:
<Empty>
*** ServerHelloDone
{code}