Return-Path: Delivered-To: apmail-portals-jetspeed-dev-archive@www.apache.org Received: (qmail 64951 invoked from network); 25 Jun 2008 00:06:37 -0000 Received: from hermes.apache.org (HELO mail.apache.org) (140.211.11.2) by minotaur.apache.org with SMTP; 25 Jun 2008 00:06:37 -0000 Received: (qmail 72847 invoked by uid 500); 25 Jun 2008 00:06:38 -0000 Delivered-To: apmail-portals-jetspeed-dev-archive@portals.apache.org Received: (qmail 72815 invoked by uid 500); 25 Jun 2008 00:06:38 -0000 Mailing-List: contact jetspeed-dev-help@portals.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Reply-To: "Jetspeed Developers List" Delivered-To: mailing list jetspeed-dev@portals.apache.org Received: (qmail 72804 invoked by uid 99); 25 Jun 2008 00:06:38 -0000 Received: from athena.apache.org (HELO athena.apache.org) (140.211.11.136) by apache.org (qpsmtpd/0.29) with ESMTP; Tue, 24 Jun 2008 17:06:38 -0700 X-ASF-Spam-Status: No, hits=-1998.5 required=10.0 tests=ALL_TRUSTED,WEIRD_PORT X-Spam-Check-By: apache.org Received: from [140.211.11.140] (HELO brutus.apache.org) (140.211.11.140) by apache.org (qpsmtpd/0.29) with ESMTP; Wed, 25 Jun 2008 00:05:56 +0000 Received: from brutus (localhost [127.0.0.1]) by brutus.apache.org (Postfix) with ESMTP id 83466234C14B for ; Tue, 24 Jun 2008 17:05:45 -0700 (PDT) Message-ID: <1770938677.1214352345536.JavaMail.jira@brutus> Date: Tue, 24 Jun 2008 17:05:45 -0700 (PDT) From: "David Sean Taylor (JIRA)" To: jetspeed-dev@portals.apache.org Subject: [jira] Commented: (JS2-828) JAAS authentication failure with Tomcat 5.5.24 and above. In-Reply-To: <2143164.1197149684130.JavaMail.jira@brutus> MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 7bit X-Virus-Checked: Checked by ClamAV on apache.org [ https://issues.apache.org/jira/browse/JS2-828?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=12607810#action_12607810 ] David Sean Taylor commented on JS2-828: --------------------------------------- Note: changing useContextClassLoader="true" now breaks 5.5.20 (I have not tested with each and every Tomcat version) To summarize, recommend: All new development on the 2.2 trunk should be done with 5.5.26 or higher If you want to develop with the 2.2 and use 5.5.23 or lower, change the useContextClassLoader='false' Do not use versions 5.5.24 or 5.5..25 as they are broken with the way Jetspeed creates its own realm > JAAS authentication failure with Tomcat 5.5.24 and above. > --------------------------------------------------------- > > Key: JS2-828 > URL: https://issues.apache.org/jira/browse/JS2-828 > Project: Jetspeed 2 > Issue Type: Bug > Environment: Tomcat >= 5.5.24 > Reporter: Mohan Kannapareddy > Assignee: Ate Douma > Priority: Critical > Fix For: 2.2 > > > Immediately after logging into the portal, the URL address box in the browser displays: > http://localhost:20000/jetspeed/login/redirector > ====================== > And the page displays: > HTTP Status 403 - Access to the requested resource has been denied > type Status report > message Access to the requested resource has been denied > description Access to the specified resource (Access to the requested resource has been denied) has been forbidden. > Apache Tomcat/5.5.25 > ====================== > I believe this is the same behavior in Tomcat 6.0.x and I get the same thing in GlassFish v2-b58g. > This does *NOT* happen in Tomcat 5.5.23 or lower versions. Something changed between 5.5.23 and 5.5.25. > Also, after the login post if you just type in the URL http://<>/jetspeed, the page appears normally and you can > function. > I do not know whether it is relevant but at least GlassFish appears to record the following in the server.log. > Unable to set request character encoding to UTF-8 from context /jetspeed, because request parameters have already been read, or ServletRequest.getReader() has already been called -- This message is automatically generated by JIRA. - You can reply to this email to add a comment to the issue online. --------------------------------------------------------------------- To unsubscribe, e-mail: jetspeed-dev-unsubscribe@portals.apache.org For additional commands, e-mail: jetspeed-dev-help@portals.apache.org