-
Bug
-
Resolution: Done
-
Blocker
-
None
In EAP 7.0 there was possible to configure fallback (e.g. BASIC) authentication, if client does not support SPNEGO authentication. In EAP 7.1 this feature does not work anymore.
In EAP 7.0 server returns multiple chalanges (Negotiate/Basic) and client could choose which he will use.
EAP 7.0
HTTP/1.1 401 Unauthorized
Connection: keep-alive
WWW-Authenticate: Negotiate
WWW-Authenticate: Basic realm="FallBackKerberosRealm"
X-Frame-Options: SAMEORIGIN
Content-Length: 77
Content-Type: text/html
Date: Mon, 30 Jan 2017 11:02:45 GMT
<html><head><title>Error</title></head><body>401 - Unauthorized</body></html>
In EAP 7.1 (with same configuration) server returns only one chalange - Negotiate so client not supporting SPNEGO, can't fallback to Basic.
EAP 7.1
HTTP/1.1 401 Unauthorized Connection: keep-alive WWW-Authenticate: Negotiate X-Frame-Options: SAMEORIGIN Content-Length: 77 Content-Type: text/html Date: Mon, 30 Jan 2017 11:01:28 GMT <html><head><title>Error</title></head><body>401 - Unauthorized</body></html>
- clones
-
JBEAP-8569 Legacy Kerberos in management, unable to configure fallback authentication.
- Closed
- is blocked by
-
WFCORE-2266 Ensure remaining legacy realm components have Elytron wrappers.
- Resolved