[
https://issues.apache.org/jira/browse/PROTON-1354?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16509688#comment-16509688
]
Andrew Stitcher commented on PROTON-1354:
-----------------------------------------
I think the problematic mechanisms are GSS-SPNEGO and GSSAPI because if the
server offers them and the client has any kerberos session it will completely
fail the sasl exchange if the server is is not known to the client rather than
just not choose those mechanisms.
As kerberos is latent in the environment this can be puzzling as there is no
sign that kerberos is set up.
This produces a very puzzling error, that is quite hard to work around without
setting the client mechanisms up explicitly - in other words needs the client
code modified.
> Disable problematic SASL mechanisms if they are not explicitly enabled
> ----------------------------------------------------------------------
>
> Key: PROTON-1354
> URL: https://issues.apache.org/jira/browse/PROTON-1354
> Project: Qpid Proton
> Issue Type: Improvement
> Components: proton-c
> Reporter: Justin Ross
> Assignee: Andrew Stitcher
> Priority: Major
> Labels: sasl, usability
>
--
This message was sent by Atlassian JIRA
(v7.6.3#76005)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]