-
Bug
-
Resolution: Done
-
Critical
-
1.1.0.Beta42
-
None
-
None
When Elytron client configuration file includes sasl-mechanism-selector with string which contains more mechanisms then only the last mentioned mechanism is used. In correct behavior it should use all given mechanisms in given order, see [1].
In case when the last given mechanism is supported by server then it tries to authenticate, otherwise no mechanism is used to attempt to authenticate.
For example, following element for selector can be used in Elytron client configuration file:
<sasl-mechanism-selector selector="PLAIN DIGEST-MD5 ANONYMOUS JBOSS-LOCAL-USER"/>
When only DIGEST-MD5 is supported by server then it works only if DIGEST-MD5 is the last mechanism in selector string.
- clones
-
JBEAP-11070 Only the last mechanism selector is used in Elytron client configuration
- Closed