Specific attributes for principal null were not requested

Christopher Bongaarts cab at umn.edu
Thu Sep 13 13:13:41 EDT 2012


On 9/12/2012 5:06 PM, Cantor, Scott wrote:

> If you have sticky sessions covering the duration of the login process
> from request to response, then it has nothing to do with your load
> balancer. It has nothing to do with the client. There is no way to have a
> null identity and not have a bug. It's a bug by definition. Even if the
> load balancer was broken, that doesn't mean the IdP is supposed to pass
> control on without an identity.

The one place I think I saw it before was when using the RemoteUser 
login handler, and the protected endpoint wasn't properly protected and 
REMOTE_USER wasn't getting set.

But that wouldn't have anything to do with the UserPassword handler or 
JAAS...

-- 
%%  Christopher A. Bongaarts   %%  cab at umn.edu          %%
%%  OIT - Identity Management  %%  http://umn.edu/~cab  %%
%%  University of Minnesota    %%  +1 (612) 625-1809    %%


More information about the users mailing list