Back to bug 1030053

Who When What Removed Added
Derek Horton 2013-11-13 20:02:13 UTC Assignee anil.saldhana darran.lofthouse
Darran Lofthouse 2013-11-14 10:33:17 UTC Status NEW ASSIGNED
Derek Horton 2014-04-01 17:47:24 UTC Link ID JBoss Issue Tracker SECURITY-815
Derek Horton 2014-04-08 18:23:09 UTC Target Release --- EAP 6.3.0
Summary The NegotiationAuthenticator loses post data [GSS] (6.3.0) The NegotiationAuthenticator loses post data
Derek Horton 2014-04-08 18:25:18 UTC Blocks 1085497
Derek Horton 2014-04-08 18:26:11 UTC Blocks 1085497
Depends On 1085497
Derek Horton 2014-04-08 18:37:52 UTC Blocks 1085504
Derek Horton 2014-04-08 18:52:30 UTC Blocks 1085497
Depends On 1085497
Derek Horton 2014-04-08 19:00:16 UTC Assignee darran.lofthouse dehort
Derek Horton 2014-04-16 20:30:09 UTC Status ASSIGNED POST
Scott Mumford 2014-05-13 02:57:57 UTC CC smumford
Doc Text In previous versions of JBoss EAP 6, it was found that the `NegotiationAuthenticator` would lose any SAMLRequest parameter if it was being used in conjunction with PicketLInk and HTTP_POST binding. This resulted in users remaining at the IDP landing page, even after successful authentication. The NegotiationAuthenticator has been patched in this release of the product and the issue no longer presents.
Tom WELLS 2014-05-14 02:09:03 UTC CC dehort, twells
Flags needinfo?(dehort)
Derek Horton 2014-05-14 13:51:57 UTC Flags needinfo?(dehort)
Derek Horton 2014-05-14 14:16:43 UTC Status POST ON_QA
Target Milestone --- ER4
Hynek Mlnarik 2014-05-14 14:55:36 UTC Status ON_QA VERIFIED
CC hmlnarik
Nidhi 2014-05-15 05:04:06 UTC CC nchaudha
Doc Text In previous versions of JBoss EAP 6, it was found that the `NegotiationAuthenticator` would lose any SAMLRequest parameter if it was being used in conjunction with PicketLInk and HTTP_POST binding. This resulted in users remaining at the IDP landing page, even after successful authentication. The NegotiationAuthenticator has been patched in this release of the product and the issue no longer presents. In previous versions of JBoss EAP 6, it was found that the `NegotiationAuthenticator` would lose any SAMLRequest parameter if it was being used in conjunction with PicketLInk and HTTP_POST binding. This resulted in users remaining at the IDP landing page, even after successful authentication. This issue will be resolved in a future release of the product.
Doc Type Bug Fix Known Issue
Nidhi 2014-05-15 05:04:49 UTC Target Milestone ER4 ER3
Nidhi 2014-05-15 05:27:17 UTC Target Milestone ER3 ER4
Tom WELLS 2014-05-15 09:17:07 UTC Doc Text In previous versions of JBoss EAP 6, it was found that the `NegotiationAuthenticator` would lose any SAMLRequest parameter if it was being used in conjunction with PicketLInk and HTTP_POST binding. This resulted in users remaining at the IDP landing page, even after successful authentication. This issue will be resolved in a future release of the product. In previous versions of JBoss EAP 6, it was found that the `NegotiationAuthenticator` would lose any SAMLRequest parameter if it was being used in conjunction with PicketLInk and HTTP_POST binding. This resulted in users remaining at the IDP landing page, even after successful authentication. The NegotiationAuthenticator has been patched in this release of the product and the issue no longer presents.
Doc Type Known Issue Bug Fix
mark yarborough 2014-06-28 15:29:04 UTC Status VERIFIED CLOSED
Resolution --- CURRENTRELEASE
Last Closed 2014-06-28 11:29:04 UTC

Back to bug 1030053