Emmanuel Lécharny created DIRAPI-445:
----------------------------------------
Summary: GSSAPI bind silently replaces JVM-global JAAS and
Kerberos configuration
Key: DIRAPI-445
URL: https://issues.apache.org/jira/browse/DIRAPI-445
Project: Directory Client API
Issue Type: Bug
Affects Versions: 2.1.8
Reporter: Emmanuel Lécharny
Fix For: 2.1.9
An app server's container realm uses a non-Kerberos *JAAS* _LoginModule_.
A background task performs one *GSSAPI* *LDAP* bind.
>From then on _Configuration.getConfiguration()_ returns
>_Krb5LoginConfiguration_ and every container login activates _Krb5LoginModule_
>instead of the configured module — co-resident authentication breaks or
>misroutes; concurrently, a second *GSSAPI* bind can read the first bind's
>_krb5.conf _and authenticate against the wrong *KDC*.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]