[jboss-jira] [JBoss JIRA] (WFLY-5022) The server requires JASPI authentication even if no security-constraint is defined
Stuart Douglas (JIRA)
issues at jboss.org
Tue Jul 28 22:29:03 EDT 2015
[ https://issues.jboss.org/browse/WFLY-5022?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13093725#comment-13093725 ]
Stuart Douglas commented on WFLY-5022:
--------------------------------------
Does this still occur if you disable proactive auth? (<proactive-authentication>false</proactive-authentication> in jboss-web.xml)
> The server requires JASPI authentication even if no security-constraint is defined
> ----------------------------------------------------------------------------------
>
> Key: WFLY-5022
> URL: https://issues.jboss.org/browse/WFLY-5022
> Project: WildFly
> Issue Type: Bug
> Components: Security, Web (Undertow)
> Affects Versions: 10.0.0.Alpha6
> Reporter: Josef Cacek
> Assignee: Darran Lofthouse
> Priority: Critical
>
> If JASPI authentication is configured in security domain, then the server requires authentication even if no security-constraint is defined for web application which uses the security domain.
> With the classic authentication is the behavior correct.
--
This message was sent by Atlassian JIRA
(v6.3.15#6346)
More information about the jboss-jira
mailing list