michael-o commented on PR #819: URL: https://github.com/apache/tomcat/pull/819#issuecomment-2668906926
> > It is not that easy and I do not agree with that. Here are cases which will not work: > > As the OP has indicated, they are already using a solution along these lines and it works for them. > > > * SPNEGO is performed, but access through LDAP uses a service account to perform a single or SASL bind. Hence, no delegated credential is used. > > This works already. If the delegated credential is presented, it will be used. No, you misunderstood what I have written. You cannot expect the bind to use Kerbwros at all. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org For queries about this service, please contact Infrastructure at: us...@infra.apache.org --------------------------------------------------------------------- To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org For additional commands, e-mail: dev-h...@tomcat.apache.org