Download
Abstract
Setting the WebContainer custom propery disablesecuritypreinvokeonfilters causes a security exposure.
Download Description
PK77465 resolves the following problem:
ERROR DESCRIPTION:
Setting the WebContainer custom property disablesecuritypreinvokeonfilters may result in Sign-on not be required for a secure URL. The custom property is required by some customers who use Single Sign-on (SSO) with SPNEGO.
LOCAL FIX:
None.
PROBLEM SUMMARY
USERS AFFECTED:
IBM WebSphere Application Server Version 6.1 and 7.0 Users of Single Sign-on (SSO) with SPNEGO.
PROBLEM DESCRIPTION:
RECOMMENDATION:
None
The WebContainer custom property was introduced by PK42868 to prevent a problem in which a SPNEGO TAI was called twice for the same request. However setting the property may result in Sign-on not be required for a secure URL.
PROBLEM CONCLUSION:
The WebContainer custom property has been removed and the WebContainer has been updated to ensure that a SPENGO TAI is called once for each request.
The fix for this APAR is currently targeted for inclusion in Fix Packs 6.1.0.25 and 7.0.0.5. Please refer to the
Recommended Updates page for delivery information:
http://www.ibm.com/support/docview.wss?rs=180&uid=swg27004980
Change History
Last Updated: 23 October 2009
- 23 October 2009: Added fixes for 6.1.0.23, 7.0.0.1, 7.0.0.3
Prerequisites
Download the UpdateInstaller below to install this fix.
Installation Instructions
Review the readme.txt for detailed installation instructions.
Technical Support
Contact IBM Support using SR (http://www.ibm.com/software/support/probsub.html), visit the WebSphere Application Server Support Web site (http://www.ibm.com/software/webservers/appserv/was/support/), or contact 1-800-IBM-SERV (U.S. only).
Problems (APARS) fixed
Was this topic helpful?
Document Information
Modified date:
15 June 2018
UID
swg24022479