Use of "removeRealmFromPrincipal" in "SPNEGOLoginModule" does not work.
Issue
- Using the
SPNEGOLoginModuleto facilitate integrated windows authentication for a web application.- One of the options on this login module is
removeRealmFromPrincipalwhich will remove the Kerberos realm from the principal. (jdoe@EXAMPLE.COM -> joe).
- One of the options on this login module is
- There are situations where the full kerberos principal name is returned as the principal instead of the desired principal name with the realm removed.
- The
SPNEGOLoginModuleis being used in a chained login module fashion and a subsequent login module (AdvancedADLoginModule) assumes a principal will not be attached and fails.
- The
Environment
- Red Hat JBoss Enterprise Application Platform (EAP)
- 6.1.0
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.