hc-httpclient-users mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Sebastiaan van Erk <sebs...@sebster.com>
Subject Kerberos proxy authentication issue
Date Fri, 11 Dec 2009 13:36:30 GMT
Hi,

I'm not sure it's supported yet in httpclient-4.1-alpha1, but continuing 
on my kerberos quest, I was trying the next phase: kerberos proxy 
authentication.

This time I'm requesting a public url from the target server via a 
kerberos protected squid proxy. Again I tested this with firefox, and it 
works fine. (The final phase, kerberos proxy AND kerberos server, also 
works with firefox).

However, when I add the following two lines to the Kerberos http client 
example:

HttpHost proxy = new HttpHost("tunnelproxy.servoy.com", 3128);
httpclient.getParams().setParameter(ConnRoutePNames.DEFAULT_PROXY, proxy);

The proxy authentication fails. It tries to authenticate to the service 
for the target web server instead of for the proxy service, that is, I 
get the following entry in my kdc.log:

2009-12-11T14:22:12 TGS-REQ testuser@SERVOY.COM from IPv4:85.147.225.232 
for HTTP/tunneltest.servoy.com@SERVOY.COM

But for the proxy service you need a ticket to 
HTTP/tunnelproxy.servoy.com@SERVOY.COM.

Is this a setup issue on my side, or is Kerberos proxy auth not yet 
supported, or is this a bug?

Again I included the wirelog for further details.

Best regards,
Sebastiaan

Mime
View raw message