Re: Windows Authentication: Issue 49318 vs 47679

2011-04-11 Thread Tim Whittington
On Mon, Mar 28, 2011 at 7:26 AM, Stefan Mayr wrote: > Hello everybody, > > as many others before we wanted to do single-sign-on for intranet web > applications using integrated windows authentication (negotiate because IE > sometimes tries NTLM instead of using plain kerberos - breaking all our >

Re: Windows Authentication: Issue 49318 vs 47679

2011-04-04 Thread André Warnier
Stefan Mayr wrote: Native SPNEGO in Tomcat sounds great. Waiting a little while depends on your scale of "little". Is there already some development we can follow? Will this use Java GSS? I never figured out how to configure this with Tomcat. If you are in a hurry, you may want to have a l

Re: Windows Authentication: Issue 49318 vs 47679

2011-03-29 Thread Mark Thomas
On 29/03/2011 21:18, Borut Hadžialić wrote: > On Tue, Mar 29, 2011 at 9:57 PM, Mark Thomas wrote: >> It is in scope with the caveat - as always - that it depends on what the >> final implementation looks like. I do know (from debug logging) that >> right now tokens do not allow delegation. I suspe

Re: Windows Authentication: Issue 49318 vs 47679

2011-03-29 Thread Borut Hadžialić
On Tue, Mar 29, 2011 at 9:57 PM, Mark Thomas wrote: > It is in scope with the caveat - as always - that it depends on what the > final implementation looks like. I do know (from debug logging) that > right now tokens do not allow delegation. I suspect the hardest part of > implementing this will b

Re: Windows Authentication: Issue 49318 vs 47679

2011-03-29 Thread Mark Thomas
On 29/03/2011 20:47, Borut Hadžialić wrote: > Would adding support for client credential delegation be out of scope > for this implementation or not? It is in scope with the caveat - as always - that it depends on what the final implementation looks like. I do know (from debug logging) that right

Re: Windows Authentication: Issue 49318 vs 47679

2011-03-29 Thread Borut Hadžialić
Whoops, i reversed the condition of the if statement, it should be: //check if the credentials can be delegated if (context.getCredDelegState()) { ... } On Tue, Mar 29, 2011 at 9:47 PM, Borut Hadžialić wrote: > Would adding support for client credential delegation be out of scope > for this impl

Re: Windows Authentication: Issue 49318 vs 47679

2011-03-29 Thread Borut Hadžialić
Would adding support for client credential delegation be out of scope for this implementation or not? Client credential delegation is when you use the spnego token construct a javax.security.auth.Subject instance that represents the client - which the server side application can use this to impers

Re: Windows Authentication: Issue 49318 vs 47679

2011-03-29 Thread Mark Thomas
On 29/03/2011 15:20, Mark Thomas wrote: > On 28/03/2011 22:31, Stefan Mayr wrote: >> Native SPNEGO in Tomcat sounds great. Waiting a little while depends on >> your scale of "little". Is there already some development we can follow? >> Will this use Java GSS? I never figured out how to configure th

Re: Windows Authentication: Issue 49318 vs 47679

2011-03-29 Thread Mark Thomas
On 28/03/2011 22:31, Stefan Mayr wrote: > Native SPNEGO in Tomcat sounds great. Waiting a little while depends on > your scale of "little". Is there already some development we can follow? > Will this use Java GSS? I never figured out how to configure this with > Tomcat. "little" hopefully means t

Re: Windows Authentication: Issue 49318 vs 47679

2011-03-28 Thread Stefan Mayr
Hi Mark, Am 28.03.2011 10:49, schrieb Mark Thomas: On 28/03/2011 08:42, Borut Hadžialić wrote: Hellos Stefan, if you can't fix your problem with configuration and decide that you want to solve the problem by programming, then this might help you http://blog.springsource.com/2009/09/28/spring-s

RE: Windows Authentication: Issue 49318 vs 47679

2011-03-28 Thread spring
> I should have SPNEGO support in Tomcat 7 fairly soon. This would be great! - To unsubscribe, e-mail: users-unsubscr...@tomcat.apache.org For additional commands, e-mail: users-h...@tomcat.apache.org

Re: Windows Authentication: Issue 49318 vs 47679

2011-03-28 Thread Mark Thomas
On 28/03/2011 08:42, Borut Hadžialić wrote: > Hellos Stefan, > > if you can't fix your problem with configuration and decide that you > want to solve the problem by programming, then this might help you > http://blog.springsource.com/2009/09/28/spring-security-kerberos/ > After understanding that

Re: Windows Authentication: Issue 49318 vs 47679

2011-03-28 Thread Borut Hadžialić
Hellos Stefan, if you can't fix your problem with configuration and decide that you want to solve the problem by programming, then this might help you http://blog.springsource.com/2009/09/28/spring-security-kerberos/ After understanding that article a developer should be able to add a SPNEGO imple

Windows Authentication: Issue 49318 vs 47679

2011-03-27 Thread Stefan Mayr
Hello everybody, as many others before we wanted to do single-sign-on for intranet web applications using integrated windows authentication (negotiate because IE sometimes tries NTLM instead of using plain kerberos - breaking all our kerberos-only experiments). We thought that IIS would be t