Infinispan cache configuration is not always applied to security-domain
Issue
- A software project based on Web Services running on top of EAP is affected by the following issue reported for WildFly. The security domain cache
auth-cache
is not always configured with the specified settings:
https://issues.jboss.org/browse/WFLY-3858
This is impacting the application because the user password and roles are stored in a external Active Directory server. It is not an option to use the default cache and never let user credentials to expire, an expiration time has to be set. Neither it is an option to disable the cache completely, the LDAP server will be accessed too often, impacting the overall application performance.
Is there any fix or workaround present or coming to EAP 6.x regarding this? We have tested successfully a custom Login Module that extends LdapExtLoginModul
e and provides a memory cache similar to Infinispan, but we would like this to be fixed in following updates.
Environment
- Red Hat JBoss Enterprise Application Platform (EAP)
- 6.3.0
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.