[ 
https://issues.apache.org/jira/browse/QPID-7789?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16094262#comment-16094262
 ] 

ASF subversion and git services commented on QPID-7789:
-------------------------------------------------------

Commit a039459c1ccd67ebf45842afe543bd64e52c3af1 in qpid-broker-j's branch 
refs/heads/master from [~k-wall]
[ https://git-wip-us.apache.org/repos/asf?p=qpid-broker-j.git;h=a039459 ]

QPID-7789: [Java Broker] [Management Console]  Allow saslExchangeExpiry timeout 
to be overidden.


> [Java Broker, WMC] The webclient sasl implementation should always answer a 
> challenge by sending back a response.
> -----------------------------------------------------------------------------------------------------------------
>
>                 Key: QPID-7789
>                 URL: https://issues.apache.org/jira/browse/QPID-7789
>             Project: Qpid
>          Issue Type: Bug
>          Components: Java Broker
>            Reporter: Lorenz Quack
>             Fix For: qpid-java-broker-7.0.0
>
>
> Currently the client does not always send back a response to a challenge. For 
> example in the SCRAM case when the client receives the server-final message 
> it knows that the negotiation completed but in certain circumstances the 
> broker might need another challenge/response round-trip.
> The client should respect the broker's wish and always respond to challenges. 
> The response would be empty if the client thinks the negotiation finished.
> In addition it should probably be easier for the client to detect whether a 
> message from the broker is a outcome with additional data or a challenge. 
> Currently the only distinction is that the challenge carries a "id" while the 
> outcome with data does not.
> This relates to QPID-7787.



--
This message was sent by Atlassian JIRA
(v6.4.14#64029)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to