HTTP/SPNEGO reuses old header when -Dhttp.auth.preference=kerberos is set

XMLWordPrintable

    • Type: Bug
    • Resolution: Duplicate
    • Priority: P3
    • None
    • Affects Version/s: 6u17
    • Component/s: core-libs
    • None
    • generic
    • generic

      In Java 6, we have a block of codes to detect what scheme should be chosen which also invalidate some previous authentication states. It seems that if the http.auth.preference system property is set, Java thinks there's no need to performance this detection and the old header was reused, and the server rejects it as a replay. Too bad.

            Assignee:
            Weijun Wang
            Reporter:
            Weijun Wang
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

              Created:
              Updated:
              Resolved:
              Imported:
              Indexed: