Infinispan cache configuration is not always applied to security-domain

Solution Unverified - Updated -

Issue

  • A software project based on Web Services running on top of EAP is affected by the following issue reported for WildFly. The security domain cache auth-cache is not always configured with the specified settings:

https://issues.jboss.org/browse/WFLY-3858

This is impacting the application because the user password and roles are stored in a external Active Directory server. It is not an option to use the default cache and never let user credentials to expire, an expiration time has to be set. Neither it is an option to disable the cache completely, the LDAP server will be accessed too often, impacting the overall application performance.

Is there any fix or workaround present or coming to EAP 6.x regarding this? We have tested successfully a custom Login Module that extends LdapExtLoginModule and provides a memory cache similar to Infinispan, but we would like this to be fixed in following updates.

Environment

  • Red Hat JBoss Enterprise Application Platform (EAP)
    • 6.3.0

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In

New to Red Hat?

Learn more about Red Hat subscriptions

Using a Red Hat product through a public cloud?

How to access this content