Uploaded image for project: 'JBoss Web'
  1. JBoss Web
  2. JBWEB-243

HTTPS / TLS Client certificate authentication does not give client certificate to server side

    Details

    • Type: Bug
    • Status: Open (View Workflow)
    • Priority: Major
    • Resolution: Unresolved
    • Affects Version/s: None
    • Fix Version/s: None
    • Component/s: None
    • Labels:
      None
    • Environment:

      JBoss AS 7.1.0.GA

      Description

      We use client certificate authentication (TLS) for our webservice (JAX-WS annotated EJB).

      In JBoss 5 and 6 the following code worked to fetch the client certificate in the session bean.

      MessageContext msgContext = wsContext.getMessageContext();
      HttpServletRequest request = (HttpServletRequest) msgContext.get(MessageContext.SERVLET_REQUEST);
      X509Certificate[] certificates = (X509Certificate[]) request.getAttribute("javax.servlet.request.X509Certificate");

      In JBoss AS 7.1.0.GA no certificate is retrieved.

        Gliffy Diagrams

          Attachments

            Activity

              People

              • Assignee:
                Unassigned
                Reporter:
                tomasg1 Tomas Gustavsson
              • Votes:
                2 Vote for this issue
                Watchers:
                4 Start watching this issue

                Dates

                • Created:
                  Updated: