[
https://issues.apache.org/jira/browse/DIRAPI-445?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Emmanuel Lécharny closed DIRAPI-445.
------------------------------------
> GSSAPI bind silently replaces JVM-global JAAS and Kerberos configuration
> ------------------------------------------------------------------------
>
> Key: DIRAPI-445
> URL: https://issues.apache.org/jira/browse/DIRAPI-445
> Project: Directory Client API
> Issue Type: Bug
> Affects Versions: 2.1.8
> Reporter: Emmanuel Lécharny
> Priority: Major
> Fix For: 2.1.9
>
>
> An app server's container realm uses a non-Kerberos *JAAS* _LoginModule_.
> A background task performs one *GSSAPI* *LDAP* bind.
> From then on _Configuration.getConfiguration()_ returns
> _Krb5LoginConfiguration_ and every container login activates
> _Krb5LoginModule_ instead of the configured module — co-resident
> authentication breaks or misroutes; concurrently, a second *GSSAPI* bind can
> read the first bind's _krb5.conf _and authenticate against the wrong *KDC*.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]