[jboss-jira] [JBoss JIRA] (SECURITY-903) Differently implemented password-stacking option in ClientLoginModule
Stefan Guilhen (JIRA)
issues at jboss.org
Thu Sep 24 09:59:00 EDT 2015
[ https://issues.jboss.org/browse/SECURITY-903?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
Stefan Guilhen updated SECURITY-903:
------------------------------------
Fix Version/s: PicketBox_5_0_0.Alpha2
(was: PicketBox_5_0_0.Beta1)
> Differently implemented password-stacking option in ClientLoginModule
> ---------------------------------------------------------------------
>
> Key: SECURITY-903
> URL: https://issues.jboss.org/browse/SECURITY-903
> Project: PicketBox
> Issue Type: Bug
> Reporter: Ryan Emerson
> Assignee: Ryan Emerson
> Fix For: PicketBox_5_0_0.Alpha2
>
>
> From BZ:
> "In case when some login module should use password stacking then value of password-stacking option should be set to useFirstPass. All login modules should respect it. However implemetation of org.jboss.security.ClientLoginModule uses password-stacking differently - it uses password stacking everytime when some value is set for password-stacking option (even value false). It should work same as other login modules. Current behavior can be confusing and can lead to incorrectly set server configuration."
--
This message was sent by Atlassian JIRA
(v6.4.11#64026)
More information about the jboss-jira
mailing list