Add an option to relax the JaasSecurityDomain certificate validation
--------------------------------------------------------------------

         Key: JBAS-1460
         URL: http://jira.jboss.com/jira/browse/JBAS-1460
     Project: JBoss Application Server
        Type: Feature Request
  Components: Security  
    Versions: JBossAS-4.0.1 Final,  JBossAS-3.2.7 Final    
    Reporter: Scott M Stark
 Assigned to: Scott M Stark 


It may be desirable to have client-cert authentication without requiring the 
client cert be available to the server. This is a weakened form of client-cert 
authentication that requires the client supply a client cert, but the only 
requirement is that its signed by a trusted CA. The client cert itself does not 
need to be verified. This may make sense if you are the CA signing the client 
cert.

Currently the JaasSecurityDomain and cert based login modules require a client 
cert in the associated JaasSecurityDomain keystore.


-- 
This message is automatically generated by JIRA.
-
If you think it was sent incorrectly contact one of the administrators:
   http://jira.jboss.com/jira/secure/Administrators.jspa
-
If you want more information on JIRA, or have a bug to report see:
   http://www.atlassian.com/software/jira



-------------------------------------------------------
SF email is sponsored by - The IT Product Guide
Read honest & candid reviews on hundreds of IT Products from real users.
Discover which products truly live up to the hype. Start reading now.
http://ads.osdn.com/?ad_id=6595&alloc_id=14396&op=click
_______________________________________________
JBoss-Development mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/jboss-development

Reply via email to