-
Feature Request
-
Resolution: Won't Do
-
Major
-
None
-
10.0.0.Final, 10.1.0.Final
-
None
-
Tested on Windows 7
In securitydomain we can set "casche-type" to infinispan. Auntentication request ara now stored in infinispan casch, but any settings of this casche (configured in infinispan subsystem) are not applied. Casche is always stored in memory and never expiries.
This is serious security issue because after first authentication request credentials, will never be verified again.