Emmanuel Lécharny created DIRAPI-445:
----------------------------------------

             Summary: GSSAPI bind silently replaces JVM-global JAAS and 
Kerberos configuration
                 Key: DIRAPI-445
                 URL: https://issues.apache.org/jira/browse/DIRAPI-445
             Project: Directory Client API
          Issue Type: Bug
    Affects Versions: 2.1.8
            Reporter: Emmanuel Lécharny
             Fix For: 2.1.9


An app server's container realm uses a non-Kerberos *JAAS* _LoginModule_.
A background task performs one *GSSAPI* *LDAP* bind.
>From then on _Configuration.getConfiguration()_ returns 
>_Krb5LoginConfiguration_ and every container login activates _Krb5LoginModule_ 
>instead of the configured module — co-resident authentication breaks or 
>misroutes; concurrently, a second *GSSAPI* bind can read the first bind's 
>_krb5.conf _and authenticate against the wrong *KDC*.




--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to