https://issues.apache.org/bugzilla/show_bug.cgi?id=50803

Mark Thomas <ma...@apache.org> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
             Status|NEW                         |RESOLVED
         Resolution|                            |INVALID

--- Comment #4 from Mark Thomas <ma...@apache.org> 2011-02-17 17:09:25 EST ---
The Realm interface will not be changed for security reasons.

The reason for a login failure should not be propagated to the user. If it
were, that would be a security vulnerability of a similar nature to
CVE-2009-0580.

-- 
Configure bugmail: https://issues.apache.org/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.

---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org
For additional commands, e-mail: dev-h...@tomcat.apache.org

Reply via email to