[ 
https://issues.apache.org/jira/browse/DIRAPI-445?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Emmanuel Lécharny closed DIRAPI-445.
------------------------------------

> GSSAPI bind silently replaces JVM-global JAAS and Kerberos configuration
> ------------------------------------------------------------------------
>
>                 Key: DIRAPI-445
>                 URL: https://issues.apache.org/jira/browse/DIRAPI-445
>             Project: Directory Client API
>          Issue Type: Bug
>    Affects Versions: 2.1.8
>            Reporter: Emmanuel Lécharny
>            Priority: Major
>             Fix For: 2.1.9
>
>
> An app server's container realm uses a non-Kerberos *JAAS* _LoginModule_.
> A background task performs one *GSSAPI* *LDAP* bind.
> From then on _Configuration.getConfiguration()_ returns 
> _Krb5LoginConfiguration_ and every container login activates 
> _Krb5LoginModule_ instead of the configured module — co-resident 
> authentication breaks or misroutes; concurrently, a second *GSSAPI* bind can 
> read the first bind's _krb5.conf _and authenticate against the wrong *KDC*.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to