Uploaded image for project: 'CXF'
  1. CXF
  2. CXF-5098

References to Kerberos Tokens are not created correctly in responses

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Major
    • Resolution: Fixed
    • None
    • 2.6.9, 2.7.6
    • None
    • None
    • Unknown

    Description


      When a service secured with a KerberosToken policy assertion responds to the client, it is incorrectly using a wsse:Reference to the original BinarySecurityToken in some cases. Instead it should be using a KeyIdentifier with the SHA-1 of the AP-REQ bytes.

      Attachments

        Activity

          People

            coheigea Colm O hEigeartaigh
            coheigea Colm O hEigeartaigh
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: