-
Bug
-
Resolution: Obsolete
-
Major
-
JBossAS-3.2.8.SP1
-
None
-
All
In org.jboss.web.tomcat.security.JBossSecurityMgrRealm when authenticate with certificate the method
SubjectSecurityManager.isValid(Principal, X509Certificate[])
is called instead of
SubjectSecurityManager.isValid(Principal, X509Certificate[], Subject)
So the subject wich is stored in the SecurityAssociation is empty and the hasRole always return false.