[jboss-jira] [JBoss JIRA] (SECURITY-933) The root cause of login module failures gets lost when multiple login modules are stacked
Tomas Hofman (JIRA)
issues at jboss.org
Thu May 19 05:37:00 EDT 2016
[ https://issues.jboss.org/browse/SECURITY-933?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
Tomas Hofman updated SECURITY-933:
----------------------------------
Bugzilla References: (was: https://bugzilla.redhat.com/show_bug.cgi?id=1288668)
> The root cause of login module failures gets lost when multiple login modules are stacked
> -----------------------------------------------------------------------------------------
>
> Key: SECURITY-933
> URL: https://issues.jboss.org/browse/SECURITY-933
> Project: PicketBox
> Issue Type: Bug
> Components: Negotiation
> Reporter: Tomas Hofman
> Assignee: Tomas Hofman
> Fix For: Negotiation_3_0_1_Final
>
>
> https://bugzilla.redhat.com/show_bug.cgi?id=1288668
> The root cause of login module failures gets lost when multiple login modules are stacked and the "flag" attribute is set to "optional".
> When the login attempt fails (invalid bindCredential on the LdapExtLoginModule for example) the authentication request will continue to the next login module in the stack. In this situation, the exceptions "cause" attribute is getting overwritten during the processing of the other login modules. This results in the actual cause to get lost during processing.
> This makes troubleshooting authentication failures difficult.
--
This message was sent by Atlassian JIRA
(v6.4.11#64026)
More information about the jboss-jira
mailing list