Uploaded image for project: 'JBoss Enterprise Application Platform'
  1. JBoss Enterprise Application Platform
  2. JBEAP-4133

[GSS](7.1.z) SPNEGO performance optimalization by avoiding one network roundtrip

XMLWordPrintable

    • Icon: Enhancement Enhancement
    • Resolution: Obsolete
    • Icon: Major Major
    • None
    • None
    • Security
    • None

      Currently if
      1. Client sends mechanisms in these order "Kerberos V5 Legacy", "Kerberos V5" + valid kerberos ticket
      2. EAP server sends accept_incomplete (Continuation required) and forces usage of "Kerberos V5"
      3. Client sends again the ticket
      4. Server sends accept_complete

      I wonder is there a chance EAP server can omit one network roundtrip?

      1. Client sends mechanisms in these order "Kerberos V5 Legacy", "Kerberos V5" + valid kerberos ticket
      2. EAP server sends accept_complete based on that "Kerberos V5" is present and valid kerberos ticket is provided

      It could bring big performance gain, because one network client-server roundtrip could be saved.

              dvilkola@redhat.com Diana Krepinska (Inactive)
              mchoma@redhat.com Martin Choma
              Votes:
              0 Vote for this issue
              Watchers:
              10 Start watching this issue

                Created:
                Updated:
                Resolved: