[jboss-jira] [JBoss JIRA] (SECURITY-846) Remote EJB client using SPNEGO authentication is not thread safe

Tom Fonteyne (JIRA) issues at jboss.org
Tue Jun 17 06:08:24 EDT 2014


Tom Fonteyne created SECURITY-846:
-------------------------------------

             Summary: Remote EJB client using SPNEGO authentication is not thread safe
                 Key: SECURITY-846
                 URL: https://issues.jboss.org/browse/SECURITY-846
             Project: PicketBox 
          Issue Type: Bug
      Security Level: Public (Everyone can see)
          Components: Negotiation
    Affects Versions: Negotiation_2_1_3
         Environment: JBoss EAP 5.2 with JBPAPP-10613 patch installed
            Reporter: Tom Fonteyne
            Assignee: Darran Lofthouse


A standalone program uses SPNEGO authentication to call an EJB on the server from several threads at the same time. Some calls will work, some will throw "Invalid User" exceptions



--
This message was sent by Atlassian JIRA
(v6.2.6#6264)


More information about the jboss-jira mailing list