Thanks Andrei. I did this and KerberosTokenValidator picked it up. All working fine now.
I have another question and was wondering if you can help? I'm getting my caller principal via wscontext and need to check its group membership within one of active directory groups. What is the best way to achieve this? Many thanks, Smkheir -- View this message in context: http://cxf.547215.n5.nabble.com/cxf-kerberos-karaf-blueprint-tp5749380p5749462.html Sent from the cxf-user mailing list archive at Nabble.com.
