[jboss-jira] [JBoss JIRA] (WFLY-5022) The server requires JASPI authentication even if no security-constraint is defined

Josef Cacek (JIRA) issues at jboss.org
Tue Jul 28 07:50:05 EDT 2015


Josef Cacek created WFLY-5022:
---------------------------------

             Summary: The server requires JASPI authentication even if no security-constraint is defined
                 Key: WFLY-5022
                 URL: https://issues.jboss.org/browse/WFLY-5022
             Project: WildFly
          Issue Type: Bug
          Components: Security, Web (Undertow)
            Reporter: Josef Cacek
            Assignee: Darran Lofthouse
            Priority: Critical


If JASPI authentication is configured in security domain, then the server requires authentication even if no security-constraint is defined for web application which uses the security domain.

With the classic authentication is the behavior correct. Also the EAP 6.x with jaspi works correctly.



--
This message was sent by Atlassian JIRA
(v6.3.15#6346)


More information about the jboss-jira mailing list