[ 
https://issues.apache.org/jira/browse/PROTON-1354?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16509688#comment-16509688
 ] 

Andrew Stitcher commented on PROTON-1354:
-----------------------------------------

I think the problematic mechanisms are GSS-SPNEGO and GSSAPI because if the 
server offers them and the client has any kerberos session it will completely 
fail the sasl exchange if the server is is not known to the client rather than 
just not choose those mechanisms.

As kerberos is latent in the environment this can be puzzling as there is no 
sign that kerberos is set up.

This produces a very puzzling error, that is quite hard to work around without 
setting the client mechanisms up explicitly - in other words needs the client 
code modified.

> Disable problematic SASL mechanisms if they are not explicitly enabled
> ----------------------------------------------------------------------
>
>                 Key: PROTON-1354
>                 URL: https://issues.apache.org/jira/browse/PROTON-1354
>             Project: Qpid Proton
>          Issue Type: Improvement
>          Components: proton-c
>            Reporter: Justin Ross
>            Assignee: Andrew Stitcher
>            Priority: Major
>              Labels: sasl, usability
>




--
This message was sent by Atlassian JIRA
(v7.6.3#76005)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to