[jboss-jira] [JBoss JIRA] (SECURITY-629) Create a new LoginModule to handle the server authentication

Darran Lofthouse (JIRA) jira-events at lists.jboss.org
Mon Jul 2 11:40:13 EDT 2012


     [ https://issues.jboss.org/browse/SECURITY-629?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Darran Lofthouse resolved SECURITY-629.
---------------------------------------

    Resolution: Out of Date


We are almost at the point where JBoss Negotiation can be deprecated in AS 7.2 - the use of these special domain definitions will become redundant.

                
> Create a new LoginModule to handle the server authentication
> ------------------------------------------------------------
>
>                 Key: SECURITY-629
>                 URL: https://issues.jboss.org/browse/SECURITY-629
>             Project: PicketBox (JBoss Security and Identity Management)
>          Issue Type: Task
>      Security Level: Public(Everyone can see) 
>          Components: Negotiation
>            Reporter: Darran Lofthouse
>            Assignee: Darran Lofthouse
>             Fix For:  Negotiation_2.0.3.SP4 
>
>
> If we supply a module of our own to handle the server authentication we can solve a couple of problems: -
>  1 - Detect which Krb5LoginModule is actually available without needing different config for different JVMs
>  2 - Allow a username / password auth even though the identity will be used later with GSSAPI

--
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators: https://issues.jboss.org/secure/ContactAdministrators!default.jspa
For more information on JIRA, see: http://www.atlassian.com/software/jira

        


More information about the jboss-jira mailing list