Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.

Bug 1085503

Summary: [GSS] (6.2.x) JBoss Negotiation should fallback to form authentication instead of returning 401
Product: [JBoss] JBoss Enterprise Application Platform 6 Reporter: Derek Horton <dehort>
Component: SecurityAssignee: Derek Horton <dehort>
Status: CLOSED CURRENTRELEASE QA Contact: Josef Cacek <jcacek>
Severity: unspecified Docs Contact: Russell Dickenson <rdickens>
Priority: unspecified    
Version: 6.2.1CC: bbaranow, cdewolf, dehort, olukas, smumford
Target Milestone: CR2   
Target Release: EAP 6.2.3   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
In previous versions of JBoss EAP 6, an invalid entry in the KDC would result in users being presented with an HTTP 401 error, instead of the login form. In this release the code has been updated to capture invalid entries in the KDC and return the login form as expected.
Story Points: ---
Clone Of: 1085500 Environment:
Last Closed: 2014-06-09 12:46:32 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1085500    
Bug Blocks: 1067532, 1085506    

Description Derek Horton 2014-04-08 18:32:33 UTC
Description of problem:
JBoss Negotiation should fallback to form authentication instead of returning 401

Steps to Reproduce:
1.  Configured an invalid KDC
2.  Hit the JBoss Negotiation Toolkit SecuredServlet (test 3)
3.  A form should be returned instead of a 401

Comment 1 baranowb 2014-04-11 06:33:23 UTC
Assigning to pskopek since he pleaded to PL issues for EAP6

Comment 2 baranowb 2014-04-15 11:59:02 UTC
Assigning back to derek, this is negotiation issue, its not part of PL as I assumed.

Comment 3 Derek Horton 2014-04-16 20:35:40 UTC
PR
https://github.com/wildfly/jboss-negotiation/pull/4

Comment 4 Ondrej Lukas 2014-05-06 13:23:13 UTC
Verified in EAP 6.2.3.CR2.

Comment 5 Nichola Moore 2014-05-08 05:12:24 UTC
Please can you add Doc Text. Thank you.

Comment 7 JBoss JIRA Server 2014-09-01 08:00:14 UTC
Hrishi Salvi <hrishishikesh.salvi> updated the status of jira SECURITY-640 to Closed

Comment 8 JBoss JIRA Server 2014-09-01 12:05:56 UTC
Darran Lofthouse <darran.lofthouse> updated the status of jira SECURITY-640 to Reopened

Comment 9 JBoss JIRA Server 2014-09-01 12:06:24 UTC
Darran Lofthouse <darran.lofthouse> updated the status of jira SECURITY-640 to Resolved